Security Configuration Flaw in Yamcs Framework Exposes Roles and Privileges
CVE-2026-55547
4.3MEDIUM
What is CVE-2026-55547?
Yamcs, a mission control framework, is affected by a vulnerability that omits necessary access control checks in its IamApi endpoints. Specifically, authenticated users can exploit this flaw to list roles and privileges through GET requests to /api/roles, /api/roles/{name}, and /api/privileges, potentially leading to unauthorized privilege escalation. This issue has been addressed in the recent releases of Yamcs, specifically versions 5.12.8 and 5.13.2.
Affected Version(s)
yamcs < 5.12.8 < 5.12.8
yamcs >= 5.13.0, < 5.13.2 < 5.13.0, 5.13.2
