CVE-2026-55559
Last modified
CVE-2026-55559 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs inserts templateArgs from POST /api/instances and PATCH /api/instances/{instance} into YAML through VarStatement.append in yamcs-core/src/main/java/org/yamcs/templating/VarStatement.java without YAML-context escaping. EPSS estimates a 0.55% chance of exploitation in the next 30 days.
Description
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs inserts templateArgs from POST /api/instances and PATCH /api/instances/{instance} into YAML through VarStatement.append in yamcs-core/src/main/java/org/yamcs/templating/VarStatement.java without YAML-context escaping. The rendered configuration is parsed by YamcsServer.createInstance and loaded by YamcsServerInstance, allowing an attacker to inject a services entry for org.yamcs.ProcessRunner. Deployments without security.yaml expose the operation through the guest superuser, while secured deployments require SystemPrivilege.CreateInstances. Successful exploitation executes commands as the Yamcs service account. This issue is fixed in versions 5.12.8 and 5.13.2.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| yamcs | yamcs | < 5.12.8; >= 5.13.0, < 5.13.2 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-55559?
How severe is CVE-2026-55559?
How do I fix CVE-2026-55559?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-55553urllib is an HTTP client for Node.js that supports authentic…7.5
- CVE-2026-55554Dompdf is an HTML to PDF converter for PHP. In versions 3.15…7.5
- CVE-2026-55555Dompdf is an HTML to PDF converter for PHP. Versions 3.15 an…7.5
- CVE-2026-55556Rsyslog is a rocket-fast system for log processing. From 8.2…8.2
- CVE-2026-55557browse-mcp is a Playwright-based headless-browser MCP server…8.6
- CVE-2026-55558aiosmtplib is an asynchronous SMTP client for use with async…5.9
- CVE-2026-5556A security vulnerability has been detected in badlogic pi-mo…6.3
- CVE-2026-55563Feast is the open source feature store for AI and machine le…8.9
- CVE-2026-55564FreeRDP is a free implementation of the Remote Desktop Proto…7.1
- CVE-2026-55565Yamcs is a mission control framework. Prior to 5.12.8 and 5.…9.9
- CVE-2026-55566Yamcs is a mission control framework. Prior to 5.12.8 and 5.…4.3
- CVE-2026-55567BleachBit cleans files to free disk space and to maintain pr…7.8
Are you affected by CVE-2026-55559?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
