{"id":"CVE-2026-55548","title":"Yamcs is a mission control framework","summary":"Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, the PacketsApi.exportPackets endpoint in yamcs-core/src/main/java/org/yamcs/http/api/PacketsApi.java failed to enforce object-level ReadPacket privileges when a request om…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-284","CWE-862"],"vendor":"spaceapplications","product":"yamcs","affected":["yamcs < 5.12.8","yamcs >= 5.13.0, < 5.13.2"],"patched":["yamcs 5.13.2"],"published":"2026-07-16","updated":"2026-07-20","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-55548","references":[{"url":"https://github.com/yamcs/yamcs/commit/b566beceba98cc35514b0e1519be126b8c5a0438","label":"security-advisories@github.com"},{"url":"https://github.com/yamcs/yamcs/commit/c743cc3acf5b5c53ff5181b94eacc21340f70dd9","label":"security-advisories@github.com"},{"url":"https://github.com/yamcs/yamcs/releases/tag/yamcs-5.12.8","label":"security-advisories@github.com"},{"url":"https://github.com/yamcs/yamcs/releases/tag/yamcs-5.13.2","label":"security-advisories@github.com"},{"url":"https://github.com/yamcs/yamcs/security/advisories/GHSA-8xjq-pr36-ccgf","label":"security-advisories@github.com"},{"url":"https://github.com/yamcs/yamcs/security/advisories/GHSA-8xjq-pr36-ccgf","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd"],"epss":0.0036,"epssPercentile":0.29864,"ingestedAt":"2026-07-20T01:35:22.431Z","slug":"CVE-2026-55548","body":"## Overview\n\nYamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, the PacketsApi.exportPackets endpoint in yamcs-core/src/main/java/org/yamcs/http/api/PacketsApi.java failed to enforce object-level ReadPacket privileges when a request omitted specific packet names: with an empty name list the ctx.checkObjectPrivileges(ObjectPrivilegeType.ReadPacket, nameSet) call passed over an empty set, no WHERE pname IN filter was applied to the resulting SELECT * FROM tm query, and the onTuple handler streamed every retrieved packet without any per-row authorization check, so a low-privileged or zero-privilege authenticated user could dump the entire raw telemetry packet archive and bypass the role-based access control model. This issue is fixed in versions 5.12.8 and 5.13.2, which enforce per-packet ReadPacket checks in exportPackets.\n\n## Affected\n\n- `yamcs < 5.12.8`\n- `yamcs >= 5.13.0, < 5.13.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `yamcs 5.13.2`","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}