PT-2026-83248 · Yamcs · Yamcs
CVE-2026-55549
·
Published
2026-08-28
·
Updated
2026-09-01
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Yamcs versions prior to 5.9.4
Description
A Reflected Cross-Site Scripting (XSS) issue exists where the application reflects the
redirect uri parameter from the 'GET /auth/authorize' endpoint into the authorize.html template without adequate HTML escaping. This occurs within the AuthHandler.java and HandlerContext.java files. An attacker can use a crafted authorization URL to execute arbitrary JavaScript in a user's browser, allowing them to access and exfiltrate browser-held authentication material, such as session tokens and refresh tokens, leading to full account compromise.Recommendations
Update to version 5.9.4.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Yamcs