PT-2026-83248 · Yamcs · Yamcs

CVE-2026-55549

·

Published

2026-08-28

·

Updated

2026-09-01

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Yamcs versions prior to 5.9.4
Description A Reflected Cross-Site Scripting (XSS) issue exists where the application reflects the redirect uri parameter from the 'GET /auth/authorize' endpoint into the authorize.html template without adequate HTML escaping. This occurs within the AuthHandler.java and HandlerContext.java files. An attacker can use a crafted authorization URL to execute arbitrary JavaScript in a user's browser, allowing them to access and exfiltrate browser-held authentication material, such as session tokens and refresh tokens, leading to full account compromise.
Recommendations Update to version 5.9.4.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55549
GHSA-RXPG-WJF8-QV9C

Affected Products

Yamcs