VendorsSpace Applicationsyamcsall versions
Vulnerabilities

Space Applications Yamcs

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2026-44596
Yamcs: No Rate Limiting on Authentication Endpoint
Published 2026-07-16 · Analyzed
9.81 PoCEPSS 0.021
CVE-2026-46562
Yamcs: Remote Code Execution via Mission Database algorithm override
Published 2026-07-16 · Analyzed
9.8EPSS 0.010
CVE-2023-45278
Directory Traversal vulnerability in the storage functionality of the API in Yamcs 5.8.6 allows attackers to delete arbitrary files via crafted HTTP DELETE request.
Published 2023-10-19 · Modified
9.1EPSS 0.016
CVE-2026-44632
Yamcs: Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory`
Published 2026-07-16 · Analyzed
9.1EPSS 0.011
CVE-2026-46621
Yamcs: Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection
Published 2026-07-16 · Analyzed
9.1EPSS 0.011
CVE-2023-45277
Yamcs 5.8.6 is vulnerable to directory traversal (issue 1 of 2). The vulnerability is in the storage functionality of the API and allows one to escape the base directory of the buckets, freely navigate system directories, and read arbitrary files.
Published 2023-10-19 · Modified
7.5EPSS 0.010
CVE-2023-45281
An issue in Yamcs 5.8.6 allows attackers to obtain the session cookie via upload of crafted HTML file.
Published 2023-10-19 · Modified
6.1EPSS 0.004
CVE-2023-45280
Yamcs 5.8.6 allows XSS (issue 2 of 2). It comes with a Bucket as its primary storage mechanism. Buckets allow for the upload of any file. There's a way to upload an HTML file containing arbitrary JavaScript and then navigate to it. Once the user opens the file, the browser will execute the arbitrary JavaScript.
Published 2023-10-19 · Modified
5.4EPSS 0.005
CVE-2023-45279
Yamcs 5.8.6 allows XSS (issue 1 of 2). It comes with a Bucket as its primary storage mechanism. Buckets allow for the upload of any file. There's a way to upload a display referencing a malicious JavaScript file to the bucket. The user can then open the uploaded display by selecting Telemetry from the menu and navigating to the display.
Published 2023-10-19 · Modified
5.4EPSS 0.004
CVE-2026-44595
Yamcs: Unauthorized user enumeration via IAM API endpoints
Published 2026-07-16 · Modified
4.31 PoCEPSS 0.011
CVE-2026-55548
Yamcs: Insecure Direct Object Reference (IDOR) in PacketsApi allows unprivileged users to dump all telemetry packets
Published 2026-07-16 · Analyzed
4.3EPSS 0.004