CVE-2026-44632
קריטית 9.1
תיאור (מקור, אנגלית)
Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs algorithm evaluation engine org.yamcs.algorithms.JavaExprAlgorithmExecutionFactory, which dynamically compiled and evaluated user-controlled algorithm text through the Janino compiler without enforcing a secure sandbox, so an authenticated user with the ChangeMissionDatabase privilege could override an existing algorithm's text via the mission database REST API and inject Java code (for example using java.lang.Runtime) to achieve remote code execution on the underlying host operating system. This issue is fixed in versions 5.12.7 and 5.13.0, which disable algorithm editing by default.
מדדים
- CVSS 3.1
-
9.1 (CRITICAL)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H - EPSS — סבירות ניצול
- 1% (אחוזון 100) נכון ל-6/8/2026
- CWE
- CWE-94
מוצרים מושפעים
spaceapplications: yamcs
קישורים
- https://github.com/yamcs/yamcs/security/advisories/GHSA-524g-x36v-9wm6 ExploitVendor Advisory
- https://github.com/yamcs/yamcs/security/advisories/GHSA-524g-x36v-9wm6 ExploitVendor Advisory
- https://github.com/yamcs/yamcs/commit/3c550348f866af4675d2ba4a51d8d12b7c7c6011 Patch
- https://github.com/yamcs/yamcs/commit/4ff8fda642ea8c3309a4d3f379aa77b763148992 Patch
- https://github.com/yamcs/yamcs/releases/tag/yamcs-5.12.7 Release Notes
- https://github.com/yamcs/yamcs/releases/tag/yamcs-5.13.0 Release Notes