Security Configuration Flaw in Yamcs Framework Exposes Roles and Privileges
CVE-2026-55547

4.3MEDIUM

Key Information:

Vendor

Yamcs

Status
Vendor
CVE Published:
28 August 2026

What is CVE-2026-55547?

Yamcs, a mission control framework, is affected by a vulnerability that omits necessary access control checks in its IamApi endpoints. Specifically, authenticated users can exploit this flaw to list roles and privileges through GET requests to /api/roles, /api/roles/{name}, and /api/privileges, potentially leading to unauthorized privilege escalation. This issue has been addressed in the recent releases of Yamcs, specifically versions 5.12.8 and 5.13.2.

Affected Version(s)

yamcs < 5.12.8 < 5.12.8

yamcs >= 5.13.0, < 5.13.2 < 5.13.0, 5.13.2

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.