PT-2026-83245 · Yamcs · Yamcs

CVE-2026-55521

·

Published

2026-08-28

·

Updated

2026-08-28

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Yamcs versions prior to 5.12.8 Yamcs versions prior to 5.13.2
Description Yamcs contains multiple missing function-level access control flaws in its Core API. These issues allow authenticated users with low privileges to bypass Role-Based Access Control (RBAC) mechanisms, which normally use SystemPrivilege and ObjectPrivilege to restrict administrative actions and data retrieval.
Technical details include:
  • The IndexesApi omits authorization checks in the listPacketIndex and listEventIndex endpoints, allowing users to read packet and event index metadata without the ObjectPrivilegeType.ReadPacket privilege.
  • The Cop1Api fails to verify SystemPrivilege.ControlLinks in the disable, resume, initialize, and updateConfig endpoints, enabling unauthorized alteration of the COP-1 (Command Operation Procedure-1) telecommand protocol state.
  • The TimeApi allows modification of the global simulation time via the setTime endpoint without asserting any system privileges, which can disrupt processors and automated tests.
These flaws can lead to the disclosure of sensitive telemetry metadata, disruption of satellite communication link protocols, and compromise of system integrity and availability.
Recommendations Update Yamcs to version 5.12.8 or later. Update Yamcs to version 5.13.2 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55521
GHSA-962X-CCWF-8X6P

Affected Products

Yamcs