Code Execution Vulnerability in OpenC3 COSMOS by OpenC3
CVE-2026-77602

9.9CRITICAL

Key Information:

Vendor

Openc3

Status
Vendor
CVE Published:
23 September 2026

What is CVE-2026-77602?

OpenC3 COSMOS is vulnerable due to a flaw that allows authenticated non-administrator users to execute unauthorized commands via content written under the 'targets_modified/' directory. This vulnerability affects versions from 5.1.0 to 7.3.0, where user-supplied configurations can be processed and executed in various execution paths. This includes potentially dangerous interactions with the application's command handling. The risk is compounded as it allows for the alteration of internal credentials and sensitive data exposure. Users are advised to upgrade to version 7.3.0 or later to mitigate this vulnerability.

Affected Version(s)

cosmos >= 5.1.0, < 7.3.0

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.