CVE-2026-55545

Source
https://cve.org/CVERecord?id=CVE-2026-55545
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55545.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-55545
Aliases
Published
2026-08-28T17:09:53.114Z
Modified
2026-08-30T08:17:24.025614Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Yamcs: WebSocket subscription handlers omit the privilege checks their REST siblings enforce
Details

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs WebSocket subscription handlers fail to enforce the privileges required by equivalent REST endpoints. PacketsApi.subscribePackets exposes the packets WebSocket topic without ObjectPrivilegeType.ReadPacket, ProcessingApi.subscribeAlgorithmStatus exposes the algorithm-status WebSocket topic without ObjectPrivilegeType.ReadAlgorithm, and MdbOverrideApi.subscribeMdbChanges exposes the mdb-changes WebSocket topic without SystemPrivilege.GetMissionDatabase. A low-privilege authenticated user can receive telemetry packets, algorithm status, and mission database change information outside the assigned authorization scope. This issue is fixed in versions 5.12.8 and 5.13.2.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55545.json",
    "cwe_ids": [
        "CWE-862"
    ],
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/yamcs/yamcs

Affected ranges

Type
GIT
Repo
https://github.com/yamcs/yamcs
Events
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "5.12.8"
        },
        {
            "introduced": "5.13.0"
        },
        {
            "fixed": "5.13.2"
        }
    ]
}

Affected versions

Other
before-removing-cfdp-half-implemented-features
v0.*
v0.26.0
v0.26.1
v0.28.0
v0.28.0-20150811
v0.28.0-20150817
v0.28.0-20150820
v0.28.0-20150824
v0.28.0-20150825
v0.28.0-20150826
v0.28.0-20150827
v0.28.0-20150828
v0.28.0-20150901
v0.28.0-20150902
v0.28.0-20150902-2
v0.28.0-20150903
v0.29.0
v0.29.1
v0.29.1-20151214
v0.29.1-20160119
v0.29.1-20160127
v0.29.3
v0.29.3-20160608
v0.29.4
yamcs-0.*
yamcs-0.30.0
yamcs-3.*
yamcs-3.0.0
yamcs-3.1.0
yamcs-3.1.1
yamcs-3.1.2
yamcs-3.2.0
yamcs-3.2.1
yamcs-3.2.2
yamcs-3.3.0
yamcs-3.4.0
yamcs-4.*
yamcs-4.0.1
yamcs-4.1.1
yamcs-4.1.2
yamcs-4.10.0
yamcs-4.10.1
yamcs-4.10.2
yamcs-4.10.3
yamcs-4.10.4
yamcs-4.10.5
yamcs-4.10.6
yamcs-4.10.7
yamcs-4.10.8
yamcs-4.10.9
yamcs-4.2.0
yamcs-4.2.1
yamcs-4.2.2
yamcs-4.3.0
yamcs-4.3.1
yamcs-4.4.0
yamcs-4.4.1
yamcs-4.4.2
yamcs-4.7
yamcs-4.7.1
yamcs-4.7.2
yamcs-4.7.3
yamcs-4.8.0
yamcs-4.8.1
yamcs-4.9.0
yamcs-4.9.1
yamcs-4.9.2
yamcs-4.9.3
yamcs-4.9.4
yamcs-4.9.5
yamcs-5.*
yamcs-5.0.0
yamcs-5.0.1
yamcs-5.1.0
yamcs-5.1.1
yamcs-5.1.2
yamcs-5.1.3
yamcs-5.10.0
yamcs-5.10.1
yamcs-5.10.2
yamcs-5.10.3
yamcs-5.10.4
yamcs-5.10.5
yamcs-5.10.6
yamcs-5.10.7
yamcs-5.10.8
yamcs-5.10.9
yamcs-5.11.0
yamcs-5.11.1
yamcs-5.11.2
yamcs-5.11.3
yamcs-5.11.4
yamcs-5.11.5
yamcs-5.11.6
yamcs-5.11.7
yamcs-5.12.0
yamcs-5.12.1
yamcs-5.12.2
yamcs-5.12.3
yamcs-5.12.4
yamcs-5.12.5
yamcs-5.12.6
yamcs-5.12.7
yamcs-5.13.0
yamcs-5.13.1
yamcs-5.2.0
yamcs-5.3.0
yamcs-5.3.1
yamcs-5.3.2
yamcs-5.3.3
yamcs-5.3.4
yamcs-5.3.5
yamcs-5.4.0
yamcs-5.4.1
yamcs-5.4.2
yamcs-5.4.3
yamcs-5.5.0
yamcs-5.5.1
yamcs-5.5.2
yamcs-5.5.3
yamcs-5.5.4
yamcs-5.5.5
yamcs-5.5.6
yamcs-5.5.7
yamcs-5.6.0
yamcs-5.6.1
yamcs-5.6.2
yamcs-5.7.0
yamcs-5.7.1
yamcs-5.7.10
yamcs-5.7.2
yamcs-5.7.3
yamcs-5.7.4
yamcs-5.7.5
yamcs-5.7.6
yamcs-5.7.7
yamcs-5.7.8
yamcs-5.7.9
yamcs-5.8.0
yamcs-5.8.1
yamcs-5.8.2
yamcs-5.8.3
yamcs-5.8.4
yamcs-5.8.5
yamcs-5.8.6
yamcs-5.8.7
yamcs-5.8.8
yamcs-5.9.0
yamcs-5.9.1
yamcs-5.9.2
yamcs-5.9.3
yamcs-5.9.4
yamcs-5.9.5
yamcs-5.9.6
yamcs-5.9.7
yamcs-5.9.8

Database specific

vanir_signatures
[
    {
        "id": "CVE-2026-55545-058eda76",
        "target": {
            "file": "yamcs-core/src/main/java/org/yamcs/http/api/ProcessingApi.java"
        },
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "340146551253321786784414927121686203009",
                "224289927213475403291707000697219094209",
                "290335778112680187474717080400028027499",
                "216797405661219066375699046771305207882"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/yamcs/yamcs/commit/12864af555e6ca4941b01c1f1217859cc0492ce0",
        "signature_type": "Line"
    },
    {
        "id": "CVE-2026-55545-4826ccbe",
        "target": {
            "file": "yamcs-core/src/main/java/org/yamcs/http/api/PacketsApi.java"
        },
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "188977920873736465868924840529844901734",
                "184898199646703937168246046196055292854",
                "167459020196848221171151339241120211144",
                "226265477467270642228780451586897261632",
                "125925782692828852304885790363696987313",
                "289433606205023236207202667278779359328",
                "259670556228404147446008325355455404567",
                "219895840284284936979333360191721442873",
                "202608066233461779787285018881780306472",
                "263383582625416342772816928103721588646",
                "76501164473952104591481246174907693119",
                "186403368436315527654843059407033563184",
                "216841990331808643390195568814851156689",
                "108025883488574325740214871862817577848",
                "245207604354844959732343680096920002190",
                "249484233190469127600505791223713020559",
                "335509563184851930845343620655474469491",
                "62312527069211479753798226781562727235",
                "269351576346561896833544912132983202646",
                "162729035745769462382097064832580487065",
                "243261481051411246404381656557374608266",
                "227516615366538140910140041078463998317",
                "287502383433361951304189629639392944775",
                "65310976531069737486218060135412696823",
                "2406692011086387992041775835241730780",
                "177274469319357011647268547735721191774",
                "151134605616570633050502659310272249228"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/yamcs/yamcs/commit/0691731846c5a0aca81b88fabbd2cd51d56fe076",
        "signature_type": "Line"
    },
    {
        "id": "CVE-2026-55545-630cc589",
        "target": {
            "file": "yamcs-core/src/main/java/org/yamcs/http/api/PacketsApi.java"
        },
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "188977920873736465868924840529844901734",
                "184898199646703937168246046196055292854",
                "167459020196848221171151339241120211144",
                "226265477467270642228780451586897261632",
                "125925782692828852304885790363696987313",
                "289433606205023236207202667278779359328",
                "259670556228404147446008325355455404567",
                "219895840284284936979333360191721442873",
                "202608066233461779787285018881780306472",
                "263383582625416342772816928103721588646",
                "76501164473952104591481246174907693119",
                "186403368436315527654843059407033563184",
                "216841990331808643390195568814851156689",
                "108025883488574325740214871862817577848",
                "245207604354844959732343680096920002190",
                "249484233190469127600505791223713020559",
                "335509563184851930845343620655474469491",
                "62312527069211479753798226781562727235",
                "269351576346561896833544912132983202646",
                "162729035745769462382097064832580487065",
                "243261481051411246404381656557374608266",
                "227516615366538140910140041078463998317",
                "287502383433361951304189629639392944775",
                "65310976531069737486218060135412696823",
                "2406692011086387992041775835241730780",
                "177274469319357011647268547735721191774",
                "151134605616570633050502659310272249228"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/yamcs/yamcs/commit/12864af555e6ca4941b01c1f1217859cc0492ce0",
        "signature_type": "Line"
    },
    {
        "id": "CVE-2026-55545-6e40dd62",
        "target": {
            "function": "subscribeMdbChanges",
            "file": "yamcs-core/src/main/java/org/yamcs/http/api/MdbOverrideApi.java"
        },
        "deprecated": false,
        "digest": {
            "function_hash": "5579997179099033949087009307182203851",
            "length": 888.0
        },
        "signature_version": "v1",
        "source": "https://github.com/yamcs/yamcs/commit/0691731846c5a0aca81b88fabbd2cd51d56fe076",
        "signature_type": "Function"
    },
    {
        "id": "CVE-2026-55545-7b9ee342",
        "target": {
            "file": "yamcs-core/src/main/java/org/yamcs/http/api/MdbOverrideApi.java"
        },
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "99750032666829545047638303419804393026",
                "38153703607513265341060027130829092780",
                "34989243012684313119037149861052711575",
                "66578960283692809318963870445014686119"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/yamcs/yamcs/commit/12864af555e6ca4941b01c1f1217859cc0492ce0",
        "signature_type": "Line"
    },
    {
        "id": "CVE-2026-55545-7ba3fce5",
        "target": {
            "function": "subscribeAlgorithmStatus",
            "file": "yamcs-core/src/main/java/org/yamcs/http/api/ProcessingApi.java"
        },
        "deprecated": false,
        "digest": {
            "function_hash": "338736133160699786311846801775451734123",
            "length": 534.0
        },
        "signature_version": "v1",
        "source": "https://github.com/yamcs/yamcs/commit/0691731846c5a0aca81b88fabbd2cd51d56fe076",
        "signature_type": "Function"
    },
    {
        "id": "CVE-2026-55545-8c942cad",
        "target": {
            "file": "yamcs-core/src/main/java/org/yamcs/http/api/ProcessingApi.java"
        },
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "340146551253321786784414927121686203009",
                "224289927213475403291707000697219094209",
                "290335778112680187474717080400028027499",
                "216797405661219066375699046771305207882"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/yamcs/yamcs/commit/0691731846c5a0aca81b88fabbd2cd51d56fe076",
        "signature_type": "Line"
    },
    {
        "id": "CVE-2026-55545-a150f9e2",
        "target": {
            "function": "subscribeAlgorithmStatus",
            "file": "yamcs-core/src/main/java/org/yamcs/http/api/ProcessingApi.java"
        },
        "deprecated": false,
        "digest": {
            "function_hash": "338736133160699786311846801775451734123",
            "length": 534.0
        },
        "signature_version": "v1",
        "source": "https://github.com/yamcs/yamcs/commit/12864af555e6ca4941b01c1f1217859cc0492ce0",
        "signature_type": "Function"
    },
    {
        "id": "CVE-2026-55545-a391cfdc",
        "target": {
            "function": "subscribePackets",
            "file": "yamcs-core/src/main/java/org/yamcs/http/api/PacketsApi.java"
        },
        "deprecated": false,
        "digest": {
            "function_hash": "87865798686807056013638082940800160405",
            "length": 2235.0
        },
        "signature_version": "v1",
        "source": "https://github.com/yamcs/yamcs/commit/12864af555e6ca4941b01c1f1217859cc0492ce0",
        "signature_type": "Function"
    },
    {
        "id": "CVE-2026-55545-aed6113a",
        "target": {
            "function": "subscribePackets",
            "file": "yamcs-core/src/main/java/org/yamcs/http/api/PacketsApi.java"
        },
        "deprecated": false,
        "digest": {
            "function_hash": "87865798686807056013638082940800160405",
            "length": 2235.0
        },
        "signature_version": "v1",
        "source": "https://github.com/yamcs/yamcs/commit/0691731846c5a0aca81b88fabbd2cd51d56fe076",
        "signature_type": "Function"
    },
    {
        "id": "CVE-2026-55545-c83a548a",
        "target": {
            "function": "subscribeMdbChanges",
            "file": "yamcs-core/src/main/java/org/yamcs/http/api/MdbOverrideApi.java"
        },
        "deprecated": false,
        "digest": {
            "function_hash": "5579997179099033949087009307182203851",
            "length": 888.0
        },
        "signature_version": "v1",
        "source": "https://github.com/yamcs/yamcs/commit/12864af555e6ca4941b01c1f1217859cc0492ce0",
        "signature_type": "Function"
    },
    {
        "id": "CVE-2026-55545-cb8d0bed",
        "target": {
            "file": "yamcs-core/src/main/java/org/yamcs/http/api/MdbOverrideApi.java"
        },
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "99750032666829545047638303419804393026",
                "38153703607513265341060027130829092780",
                "34989243012684313119037149861052711575",
                "66578960283692809318963870445014686119"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/yamcs/yamcs/commit/0691731846c5a0aca81b88fabbd2cd51d56fe076",
        "signature_type": "Line"
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55545.json"
vanir_signatures_modified
"2026-08-30T08:17:24Z"