Back

MEDIUM

Yamcs: Unauthorized user enumeration via IAM API endpoints

Published Jul 16, 2026

Description

Yamcs is a mission control framework. Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGroup in yamcs-core did not enforce the required SystemPrivilege.ControlAccess check in yamcs-core/src/main/java/org/yamcs/http/api/IamApi.java, so any authenticated user, even one with low or no privileges, could enumerate all user accounts in the system including their usernames, superuser status, and group memberships. This issue is fixed in versions 5.12.7 and 5.13.0.

Affected products

Remediation

No remediation recorded yet.

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jul 16, 2026
Updated Jul 18, 2026
Reserved May 6, 2026
CISA Vulnrichment
Updated Jul 18, 2026
NVD
Status Modified
Modified Jul 18, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-P2RJ-MRMC-9W29