Open Redirect Vulnerability in Yamcs Framework by Yamcs
CVE-2026-55549

6.5MEDIUM

Key Information:

Vendor

Yamcs

Status
Vendor
CVE Published:
28 August 2026

What is CVE-2026-55549?

The Yamcs mission control framework contains a vulnerability that allows an attacker to exploit the redirect_uri parameter in the authorization process. This issue occurs due to insufficient HTML escaping in the handling of this parameter. As a result, a crafted URL can execute malicious JavaScript in the context of a Yamcs user's session. The script has the capability to access sensitive authentication data stored in the user's browser and transmit it to an attacker, resulting in potential account compromise. Users are advised to upgrade to version 5.9.4 to mitigate this risk.

Affected Version(s)

yamcs < 5.9.4

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.