PT-2026-83246 · Yamcs · Yamcs

CVE-2026-55545

·

Published

2026-08-28

·

Updated

2026-08-28

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Yamcs versions prior to 5.12.8 Yamcs versions prior to 5.13.2
Description WebSocket subscription handlers fail to enforce the privileges required by equivalent REST endpoints. This allows a low-privilege authenticated user to receive telemetry packets, algorithm status, and mission database change information outside their assigned authorization scope. The issue affects the following components:
  • PacketsApi.subscribePackets exposes the packets WebSocket topic without requiring ObjectPrivilegeType.ReadPacket.
  • ProcessingApi.subscribeAlgorithmStatus exposes the algorithm-status WebSocket topic without requiring ObjectPrivilegeType.ReadAlgorithm.
  • MdbOverrideApi.subscribeMdbChanges exposes the mdb-changes WebSocket topic without requiring SystemPrivilege.GetMissionDatabase.
Recommendations Update to version 5.12.8. Update to version 5.13.2.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55545
GHSA-FWWW-CP23-7F5G

Affected Products

Yamcs