Session Management Flaw in OpenC3 COSMOS Affects Authentication Security
CVE-2026-77394
What is CVE-2026-77394?
The OpenC3 COSMOS platform, which enables communication with embedded systems, is vulnerable due to an improper session management flaw. An authenticated user with 'system_set' permissions can exploit the functionality to store a shared screen. This is executed through a POST command that triggers a widget action evaluated in another user's browser session upon activation. Consequently, this vulnerability can lead to the execution of malicious scripts in the COSMOS origin, allowing the attacker to access local storage, specifically the victim's bearer token. This could result in account takeover, enabling unauthorized actions on behalf of the victim. The issue arises partly from a lenient content security policy, although the main cause is related to session management practices. The vulnerability was resolved in version 7.3.0.
Affected Version(s)
cosmos >= 5.0.6, < 7.3.0
