CVE-2026-55566Medium· 4.3▾ SunlitYamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs processes attacker-controlled data from the /ext URL route in yamcs-web/src/main/webapp/projects/webapp/src/app/core/routes/extension.matcher.ts, extension.component…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 29.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
Last analysed / modified upstream
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs processes attacker-controlled data from the /ext URL route in yamcs-web/src/main/webapp/projects/webapp/src/app/core/routes/extension.matcher.ts, extension.component.ts, and app.component.ts without checking registered plugin IDs before DOM rendering through innerHTML. A crafted URL can execute JavaScript when opened by a user. The script can read data available to the Yamcs web application and perform actions in the user context. This issue is fixed in versions 5.12.8 and 5.13.2.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
org.yamcs:yamcs-core >= 5.13.0, <= 5.13.1org.yamcs:yamcs-core <= 5.12.7Patched in:
org.yamcs:yamcs-core 5.13.2org.yamcs:yamcs-core 5.12.8Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55559Critical· 9.8Yamcs is a mission control framework
CVE-2026-55565Critical· 9.9Yamcs is a mission control framework
CVE-2026-55511Critical· 9.1Yamcs is a mission control framework
CVE-2026-55521High· 8.8Yamcs is a mission control framework
CVE-2026-55545Medium· 6.5Yamcs is a mission control framework
CVE-2026-55547Medium· 4.3Yamcs is a mission control framework