All 7 CVE vulnerabilities found in yamcs, with AI-generated Chinese analysis, references, and POCs.
Vendor: yamcs
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-55548 | Yamcs: Insecure Direct Object Reference (IDOR) in PacketsApi allows unprivileged users to dump all telemetry packets CWE-284 | 4.3 | Medium | 2026-07-16 |
| CVE-2026-46621 | Yamcs: Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection CWE-94 | 9.1 | Critical | 2026-07-16 |
| CVE-2026-46562 | Yamcs: Remote Code Execution via Mission Database algorithm override CWE-94 | 9.8 | Critical | 2026-07-16 |
| CVE-2026-44632 | Yamcs: Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory` CWE-94 | 9.1 | Critical | 2026-07-16 |
| CVE-2026-44596 | Yamcs: No Rate Limiting on Authentication Endpoint CWE-307 | 6.5 | Medium | 2026-07-16 |
| CVE-2026-44595 | Yamcs: Unauthorized user enumeration via IAM API endpoints CWE-862 | 4.3 | Medium | 2026-07-16 |
| CVE-2026-42568 | Yamcs Vulnerable to LDAP Injection in LdapAuthModule CWE-90 | 4.3 | Medium | 2026-06-10 |
All 7 known CVE vulnerabilities affecting yamcs with full Chinese analysis, references, and POCs where available.