MEDIUM
Yamcs: Unauthorized user enumeration via IAM API endpoints
Published Jul 16, 2026
4.3
MEDIUMCVSS 3.1
EPSS 1.06%
Description
Yamcs is a mission control framework. Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGroup in yamcs-core did not enforce the required SystemPrivilege.ControlAccess check in yamcs-core/src/main/java/org/yamcs/http/api/IamApi.java, so any authenticated user, even one with low or no privileges, could enumerate all user accounts in the system including their usernames, superuser status, and group memberships. This issue is fixed in versions 5.12.7 and 5.13.0.
Affected products
-
- Version < 5.12.7StatusaffectedConstraints-
- Version
- < 5.12.7
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://github.com/advisories/GHSA-p2rj-mrmc-9w29 Advisory
- https://github.com/yamcs/yamcs/commit/0e12b518f103f24681299318a30a460fe4327b88 x_refsource_MISCPatch
- https://github.com/yamcs/yamcs/commit/e90099fba98e96214217c195b6a5b87b5f46e51c x_refsource_MISCPatch
- https://github.com/yamcs/yamcs/releases/tag/yamcs-5.12.7 x_refsource_MISCRelease Notes
- https://github.com/yamcs/yamcs/releases/tag/yamcs-5.13.0 x_refsource_MISCRelease Notes
- https://github.com/yamcs/yamcs/security/advisories/GHSA-p2rj-mrmc-9w29 exploitx_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-p2rj-mrmc-9w29 | Advisory | |
| https://github.com/yamcs/yamcs/commit/0e12b518f103f24681299318a30a460fe4327b88 | x_refsource_MISCPatch | |
| https://github.com/yamcs/yamcs/commit/e90099fba98e96214217c195b6a5b87b5f46e51c | x_refsource_MISCPatch | |
| https://github.com/yamcs/yamcs/releases/tag/yamcs-5.12.7 | x_refsource_MISCRelease Notes | |
| https://github.com/yamcs/yamcs/releases/tag/yamcs-5.13.0 | x_refsource_MISCRelease Notes | |
| https://github.com/yamcs/yamcs/security/advisories/GHSA-p2rj-mrmc-9w29 | exploitx_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jul 16, 2026
Updated Jul 18, 2026
Reserved May 6, 2026
Link CVE-2026-44595
CISA Vulnrichment
GHSA-P2RJ-MRMC-9W29 Updated Jul 18, 2026