


Perceptive Security
SOC/SIEM Consultancy

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs LikeExpression.fillCode_getValueReturn in yamcs-core/src/main/java/org/yamcs/yarch/strea…
Published:
28 August 2026 at 00:00:00
Alert date:
28 August 2026 at 23:18:32
Source:
nvd.nist.gov
Critical Infrastructure, Enterprise Applications, Web Technologies
A code injection vulnerability exists in Yamcs, a mission control framework, prior to versions 5.12.8 and 5.13.2. The flaw resides in LikeExpression.fillCode_getValueReturn in LikeExpression.java, where an unescaped LIKE pattern is inserted into Java source code compiled at runtime via SimpleCompiler.cook, bypassing the escapeJavaString sanitization. The vulnerability can be triggered through multiple API endpoints including executeSql, streamSql, readRows, events, and activity searches. Attackers with access to these endpoints (ReadTables, ReadEvents, or ReadActivities permissions) can inject arbitrary Java code that executes with the privileges of the Yamcs server process. This represents a serious remote code execution risk in mission-critical environments. The issue has been patched in Yamcs versions 5.12.8 and 5.13.2, with fixes available via two separate commits on GitHub.
Technical details
Mitigation steps:
Affected products:
Yamcs
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-55565
https://github.com/yamcs/yamcs/commit/640e1598b7097b521692e89dd47a39b6cb1fc663
https://github.com/yamcs/yamcs/commit/a8fb4a0693fa62a6eb729b26016d1090dd8b289c
https://github.com/yamcs/yamcs/releases/tag/yamcs-5.12.8
https://github.com/yamcs/yamcs/releases/tag/yamcs-5.13.2
https://github.com/yamcs/yamcs/security/advisories/GHSA-c64q-hj4j-375f
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
