CVE-2026-77394
Last modified
CVE-2026-77394 is a high-severity vulnerability rated 7.6/10 on the CVSS scale. OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.0.6 until 7.3.0, an authenticated actor with system_set permission can store a shared screen through POST /openc3-api/screen whose BUTTON widget action is evaluated by openc3-cosmos-init/plugins/packages/openc3-vue-common/src/widgets/ButtonWidget.vue in another operator's browser session when the button is activated.
Description
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.0.6 until 7.3.0, an authenticated actor with system_set permission can store a shared screen through POST /openc3-api/screen whose BUTTON widget action is evaluated by openc3-cosmos-init/plugins/packages/openc3-vue-common/src/widgets/ButtonWidget.vue in another operator's browser session when the button is activated. The stored script runs in the COSMOS origin and can read localStorage.openc3Token, allowing theft of the victim's bearer token, account takeover, and actions with the victim's privileges. The permissive content security policy contributes to execution but is not the primary root cause. This issue is fixed in version 7.3.0.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-77394?
How severe is CVE-2026-77394?
How do I fix CVE-2026-77394?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-77385Kyoo is a self-hosted media server focused on movies, series…4.3
- CVE-2026-77386Kyoo is a self-hosted media server focused on movies, series…6.5
- CVE-2026-7739A weakness has been identified in justdan96 tsMuxer up to 2.…3.3
- CVE-2026-77391A security flaw has been discovered in SourceCodester Dynami…4.3
- CVE-2026-77392A weakness has been identified in SourceCodester Dynamic Inp…6.3
- CVE-2026-77393In Ignition 8.1.53 and earlier, the Gateway "Create Project …8.8
- CVE-2026-77396PJSIP is a free and open source multimedia communication lib…6.9
- CVE-2026-77399icalendar is an RFC 5545 compatible parser and generator of …6.5
- CVE-2026-7740A security vulnerability has been detected in justdan96 tsMu…3.3
- CVE-2026-77401Zope AccessControl provides a general security framework for…6.8
- CVE-2026-77403RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13…8.9
- CVE-2026-77404RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13…8.7
Are you affected by CVE-2026-77394?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
