Vulnerabilidades en yamcs

16 resultados
Análisis Vexday

O YAMCS apresenta 7 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, com 3 delas classificadas como críticas e nenhuma sob exploração ativa conhecida. A fraqueza dominante é execução de código arbitrário (CWE-94), representando risco significativo de comprometimento direto da plataforma em ambientes onde o software é exposto.

CVE-2026-44596MEDIUMYamcs: No Rate Limiting on Authentication EndpointEPSS 2.1%CVE-2026-55549MEDIUMYamcs: Reflected XSS in the URL of the Authorize EndpointEPSS 1.3%CVE-2026-44632CRITICALYamcs: Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory`EPSS 1.1%CVE-2026-46621CRITICALYamcs: Authenticated Remote Code Execution (RCE) via Jython Algorithm Code InjectionEPSS 1.1%CVE-2026-44595MEDIUMYamcs: Unauthorized user enumeration via IAM API endpointsEPSS 1.1%CVE-2026-42568MEDIUMYamcs Vulnerable to LDAP Injection in LdapAuthModuleEPSS 1.0%CVE-2026-46562CRITICALYamcs: Remote Code Execution via Mission Database algorithm overrideEPSS 1.0%CVE-2026-55559CRITICALYamcs: Remote Code Execution via instance-template argument YAML injection (createInstance)EPSS 0.8%CVE-2026-55511CRITICALYamcs: Authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs `executeSql`EPSS 0.7%CVE-2026-55565CRITICALYamcs: Authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled by Janino (`LikeExpression`)EPSS 0.7%CVE-2026-55552HIGHYamcs: Unauthenticated Directory TraversalEPSS 0.5%CVE-2026-55521HIGHYamcs : Multiple Missing Function Level Access Control vulnerabilities in Yamcs Core APIEPSS 0.5%CVE-2026-55545MEDIUMYamcs: WebSocket subscription handlers omit the privilege checks their REST siblings enforceEPSS 0.5%CVE-2026-55566MEDIUMYamcs: DOM XSS in Extension RoutingEPSS 0.4%CVE-2026-55548MEDIUMYamcs: Insecure Direct Object Reference (IDOR) in PacketsApi allows unprivileged users to dump all telemetry packetsEPSS 0.4%CVE-2026-55547MEDIUMYamcs: Missing Authorization on Role and Privilege Enumeration Endpoints Allows Any Authenticated User to Disclose Full Security ConfigurationEPSS 0.3%