Session Management Flaw in OpenC3 COSMOS Affects Authentication Security
CVE-2026-77394

7.6HIGH

Key Information:

Vendor

Openc3

Status
Vendor
CVE Published:
23 September 2026

What is CVE-2026-77394?

The OpenC3 COSMOS platform, which enables communication with embedded systems, is vulnerable due to an improper session management flaw. An authenticated user with 'system_set' permissions can exploit the functionality to store a shared screen. This is executed through a POST command that triggers a widget action evaluated in another user's browser session upon activation. Consequently, this vulnerability can lead to the execution of malicious scripts in the COSMOS origin, allowing the attacker to access local storage, specifically the victim's bearer token. This could result in account takeover, enabling unauthorized actions on behalf of the victim. The issue arises partly from a lenient content security policy, although the main cause is related to session management practices. The vulnerability was resolved in version 7.3.0.

Affected Version(s)

cosmos >= 5.0.6, < 7.3.0

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.