Yamcs Mission Control Framework Vulnerability in Service Account Execution
CVE-2026-55559
What is CVE-2026-55559?
The Yamcs Mission Control Framework is exposed to a vulnerability where template arguments from POST and PATCH requests can be inserted into YAML without proper context escaping. This flaw exists in versions preceding 5.12.8 and 5.13.2. An attacker can exploit this vulnerability to inject malicious entries, which may lead to executing arbitrary commands as the Yamcs service account. Notably, deployments lacking a security.yaml file are particularly susceptible, while secured instances require elevated privileges for exploitation. This vulnerability poses significant risks in terms of unauthorized command execution within the affected systems. For enhanced security, users are advised to upgrade to the patched versions 5.12.8 and 5.13.2.
Affected Version(s)
yamcs < 5.12.8 < 5.12.8
yamcs >= 5.13.0, < 5.13.2 < 5.13.0, 5.13.2
