Authorization Bypass in Yamcs Mission Control Framework
CVE-2026-55521
8.8HIGH
What is CVE-2026-55521?
The Yamcs mission control framework contains a vulnerability that allows authenticated low-privilege users to bypass critical authorization checks in several APIs, including IndexesApi and Cop1Api. This weakness enables unauthorized users to read sensitive telemetry metadata, alter link states, and manipulate simulation time. Such unauthorized actions can disrupt telecommand handling and compromise both the integrity and availability of the system. Users are advised to update to versions 5.12.8 or 5.13.2 to mitigate this vulnerability.
Affected Version(s)
yamcs < 5.12.8 < 5.12.8
yamcs >= 5.13.0, < 5.13.2 < 5.13.0, 5.13.2
