CVE-2026-44595
Yamcs is a mission control framework.
Does this matter?
Lower severity and a low EPSS score (1.06%). Track it; it rarely justifies an emergency change on its own.
Description
Yamcs is a mission control framework. Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGroup in yamcs-core did not enforce the required SystemPrivilege.ControlAccess check in yamcs-core/src/main/java/org/yamcs/http/api/IamApi.java, so any authenticated user, even one with low or no privileges, could enumerate all user accounts in the system including their usernames, superuser status, and group memberships. This issue is fixed in versions 5.12.7 and 5.13.0.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.06% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862
- Affected
- spaceapplications/yamcs
- Source
- security-advisories@github.com
References
- https://github.com/yamcs/yamcs/commit/0e12b518f103f24681299318a30a460fe4327b88Patch
- https://github.com/yamcs/yamcs/commit/e90099fba98e96214217c195b6a5b87b5f46e51cPatch
- https://github.com/yamcs/yamcs/releases/tag/yamcs-5.12.7Release Notes
- https://github.com/yamcs/yamcs/releases/tag/yamcs-5.13.0Release Notes
- https://github.com/yamcs/yamcs/security/advisories/GHSA-p2rj-mrmc-9w29Exploit, Vendor Advisory
- https://github.com/yamcs/yamcs/security/advisories/GHSA-p2rj-mrmc-9w29Exploit, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.