Yamcs
Spaceapplications · 11 CVEs
Yamcs: Insecure Direct Object Reference (IDOR) in PacketsApi allows unprivileged users to dump all telemetry packets
Jul 16, 2026
Yamcs: Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection
Jul 16, 2026
Yamcs: Remote Code Execution via Mission Database algorithm override
Jul 16, 2026
Yamcs: Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory`
Jul 16, 2026
Yamcs: No Rate Limiting on Authentication Endpoint
Jul 16, 2026
Yamcs: Unauthorized user enumeration via IAM API endpoints
Jul 16, 2026
An issue in Yamcs 5.8.6 allows attackers to obtain the session cookie via upload of crafted HTML file.
Oct 19, 2023
Yamcs 5.8.6 allows XSS (issue 2 of 2). It comes with a Bucket as its primary storage mechanism. Buckets allow for the u…
Oct 19, 2023
Yamcs 5.8.6 allows XSS (issue 1 of 2). It comes with a Bucket as its primary storage mechanism. Buckets allow for the u…
Oct 19, 2023
Directory Traversal vulnerability in the storage functionality of the API in Yamcs 5.8.6 allows attackers to delete arb…
Oct 19, 2023
Yamcs 5.8.6 is vulnerable to directory traversal (issue 1 of 2). The vulnerability is in the storage functionality of t…
Oct 19, 2023
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-55548 | Yamcs: Insecure Direct Object Reference (IDOR) in PacketsApi allows unprivileged users to dump all telemetry packets | MEDIUM | 0.36% | Jul 16, 2026 |
| CVE-2026-46621 | Yamcs: Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection | CRITICAL | 1.12% | Jul 16, 2026 |
| CVE-2026-46562 | Yamcs: Remote Code Execution via Mission Database algorithm override | CRITICAL | 0.98% | Jul 16, 2026 |
| CVE-2026-44632 | Yamcs: Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory` | CRITICAL | 1.12% | Jul 16, 2026 |
| CVE-2026-44596 | Yamcs: No Rate Limiting on Authentication Endpoint | CRITICAL | 2.06% | Jul 16, 2026 |
| CVE-2026-44595 | Yamcs: Unauthorized user enumeration via IAM API endpoints | MEDIUM | 1.06% | Jul 16, 2026 |
| CVE-2023-45281 | An issue in Yamcs 5.8.6 allows attackers to obtain the session cookie via upload of crafted HTML file. | MEDIUM | 0.41% | Oct 19, 2023 |
| CVE-2023-45280 | Yamcs 5.8.6 allows XSS (issue 2 of 2). It comes with a Bucket as its primary storage mechanism. Buckets allow for the upload of any file. There's a way to uplo… | MEDIUM | 0.53% | Oct 19, 2023 |
| CVE-2023-45279 | Yamcs 5.8.6 allows XSS (issue 1 of 2). It comes with a Bucket as its primary storage mechanism. Buckets allow for the upload of any file. There's a way to uplo… | MEDIUM | 0.43% | Oct 19, 2023 |
| CVE-2023-45278 | Directory Traversal vulnerability in the storage functionality of the API in Yamcs 5.8.6 allows attackers to delete arbitrary files via crafted HTTP DELETE req… | CRITICAL | 1.58% | Oct 19, 2023 |
| CVE-2023-45277 | Yamcs 5.8.6 is vulnerable to directory traversal (issue 1 of 2). The vulnerability is in the storage functionality of the API and allows one to escape the base… | HIGH | 1.00% | Oct 19, 2023 |
Showing 1 to 11 of 11 CVEs