Browse all 7 CVE security advisories affecting yamcs. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-55548 | Yamcs: Insecure Direct Object Reference (IDOR) in PacketsApi allows unprivileged users to dump all telemetry packets — yamcsCWE-284 | 4.3 | Medium | 2026-07-16 |
| CVE-2026-46621 | Yamcs: Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection — yamcsCWE-94 | 9.1 | Critical | 2026-07-16 |
| CVE-2026-46562 | Yamcs: Remote Code Execution via Mission Database algorithm override — yamcsCWE-94 | 9.8 | Critical | 2026-07-16 |
| CVE-2026-44632 | Yamcs: Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory` — yamcsCWE-94 | 9.1 | Critical | 2026-07-16 |
| CVE-2026-44596 | Yamcs: No Rate Limiting on Authentication Endpoint — yamcsCWE-307 | 6.5 | Medium | 2026-07-16 |
| CVE-2026-44595 | Yamcs: Unauthorized user enumeration via IAM API endpoints — yamcsCWE-862 | 4.3 | Medium | 2026-07-16 |
| CVE-2026-42568 | Yamcs Vulnerable to LDAP Injection in LdapAuthModule — yamcsCWE-90 | 4.3 | Medium | 2026-06-10 |
This page lists every published CVE security advisory associated with yamcs. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.