Yamcs Mission Control Framework Vulnerability in Service Account Execution
CVE-2026-55559

9.8CRITICAL

Key Information:

Vendor

Yamcs

Status
Vendor
CVE Published:
28 August 2026

What is CVE-2026-55559?

The Yamcs Mission Control Framework is exposed to a vulnerability where template arguments from POST and PATCH requests can be inserted into YAML without proper context escaping. This flaw exists in versions preceding 5.12.8 and 5.13.2. An attacker can exploit this vulnerability to inject malicious entries, which may lead to executing arbitrary commands as the Yamcs service account. Notably, deployments lacking a security.yaml file are particularly susceptible, while secured instances require elevated privileges for exploitation. This vulnerability poses significant risks in terms of unauthorized command execution within the affected systems. For enhanced security, users are advised to upgrade to the patched versions 5.12.8 and 5.13.2.

Affected Version(s)

yamcs < 5.12.8 < 5.12.8

yamcs >= 5.13.0, < 5.13.2 < 5.13.0, 5.13.2

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.