Cross-Site Scripting Vulnerability in Yamcs Mission Control Framework
CVE-2026-55566

4.3MEDIUM

Key Information:

Vendor

Yamcs

Status
Vendor
CVE Published:
28 August 2026

What is CVE-2026-55566?

Prior to specific updates, Yamcs, a mission control framework, processed unverified data from attacker-controlled URLs without proper validation of registered plugin IDs. This oversight allowed for the potential execution of JavaScript within the context of the application. When a crafted URL was accessed, the embedded script could read sensitive information and interact with the web application as the authenticated user. The issue was mitigated in versions 5.12.8 and 5.13.2, which implemented necessary security checks to prevent such attacks.

Affected Version(s)

yamcs < 5.12.8 < 5.12.8

yamcs >= 5.13.0, < 5.13.2 < 5.13.0, 5.13.2

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.