CVE-2026-46562
A flaw in Yamcs allows a privileged user to run arbitrary JavaScript that can execute OS commands on the host. The vulnerability exists in versions before 5.12.7 and can be exploited without authentication in the default configuration. It has been fixed in newer releases.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Yamcs mission control framework, versions prior to 5.12.7 (spaceapplications yamcs).
Real-world impact
An attacker with ChangeMissionDatabase privilege can inject JavaScript that calls Java classes to run arbitrary commands, effectively taking control of the Yamcs server.
Why this severity
The CVSS score of 9.8 reflects that the flaw is exploitable over the network, requires no user interaction, and grants complete compromise of confidentiality, integrity, and availability.
What to do about it
- 01Upgrade Yamcs to version 5.12.7 or later, which disables algorithm editing by default.
NVD-referenced vendor advisory
Timeline
- Jul 16, 2026 · 17d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 20, 2026 · 14d agoAdvisory updatedThe NVD record was last revised.
- Jul 20, 2026 · 14d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- github.com/yamcs/yamcs/commit/3c550348…patch
- github.com/yamcs/yamcs/commit/4ff8fda6…patch
- github.com/yamcs/yamcs/releases/tag/ya…release notes
- github.com/yamcs/yamcs/releases/tag/ya…release notes
- github.com/yamcs/yamcs/security/adviso…exploitvendor advisory