Yamcs Mission Control Framework Vulnerability in Service Account Execution
CVE-2026-55559
Key Information:
Badges
What is CVE-2026-55559?
The Yamcs Mission Control Framework is exposed to a vulnerability where template arguments from POST and PATCH requests can be inserted into YAML without proper context escaping. This flaw exists in versions preceding 5.12.8 and 5.13.2. An attacker can exploit this vulnerability to inject malicious entries, which may lead to executing arbitrary commands as the Yamcs service account. Notably, deployments lacking a security.yaml file are particularly susceptible, while secured instances require elevated privileges for exploitation. This vulnerability poses significant risks in terms of unauthorized command execution within the affected systems. For enhanced security, users are advised to upgrade to the patched versions 5.12.8 and 5.13.2.
Affected Version(s)
yamcs < 5.12.8 < 5.12.8
yamcs >= 5.13.0, < 5.13.2 < 5.13.0, 5.13.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
