Arbitrary Code Execution Vulnerability in Yamcs Mission Control Framework
CVE-2026-55511
9.1CRITICAL
What is CVE-2026-55511?
The Yamcs Mission Control Framework is susceptible to a significant vulnerability where users with SystemPrivilege.ControlArchiving can exploit the system by creating a double-quoted StreamSQL column name. This input, when processed, can lead to the generation of arbitrary Java code through various components in the system. As a result, an attacker can execute unauthorized Java code in the Yamcs server, jeopardizing mission data confidentiality and integrity. This vulnerability allows potential telemetry manipulation and denial of service attacks. The issue has been resolved in versions 5.12.8 and 5.13.2 of Yamcs.
Affected Version(s)
yamcs < 5.12.8 < 5.12.8
yamcs >= 5.13.0, < 5.13.2 < 5.13.0, 5.13.2
