CVE-2026-55547
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits SystemPrivilege.ControlAccess checks from IamApi.listRoles, Ia
CVSS
4.3
Medio
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 28 ago 2026 · Última mod.: 28 ago 2026 · CWE-285 · CWE-862
Sin historial EPSS suficiente todavía.
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits SystemPrivilege.ControlAccess checks from IamApi.listRoles, IamApi.getRole, and IamApi.listPrivileges in yamcs-core/src/main/java/org/yamcs/http/api/IamApi.java. Any authenticated account can call GET /api/roles, GET /api/roles/{name}, and GET /api/privileges to enumerate available system privileges and configured role mappings. The disclosure reveals security configuration that can support targeted privilege-escalation attempts. This issue is fixed in versions 5.12.8 and 5.13.2.
- github.comhttps://github.com/yamcs/yamcs/commit/c2aec1c242e656e48b52c7f87deea88183bb592d
- github.comhttps://github.com/yamcs/yamcs/commit/dcaec5f0b2f4231b8e313e94d79a937169c9e0ba
- github.comhttps://github.com/yamcs/yamcs/releases/tag/yamcs-5.12.8
- github.comhttps://github.com/yamcs/yamcs/releases/tag/yamcs-5.13.2
- github.comhttps://github.com/yamcs/yamcs/security/advisories/GHSA-cvw4-55pp-3hfq
- github.comhttps://github.com/yamcs/yamcs/security/advisories/GHSA-cvw4-55pp-3hfq