


Perceptive Security
SOC/SIEM Consultancy

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs inserts templateArgs from POST /api/instances and PATCH /api/instances/{instance} into Y…
Published:
28 augustus 2026 om 00:00:00
Alert date:
28 augustus 2026 om 23:18:31
Source:
nvd.nist.gov
Critical Infrastructure, Web Technologies, Enterprise Applications
A YAML injection vulnerability exists in Yamcs mission control framework prior to versions 5.12.8 and 5.13.2. The flaw resides in VarStatement.append, which inserts templateArgs from POST/PATCH API endpoints into YAML configuration without proper escaping. An attacker can inject a malicious services entry for org.yamcs.ProcessRunner into the rendered configuration, leading to arbitrary command execution as the Yamcs service account. Unsecured deployments lacking security.yaml are exposed via the guest superuser, making exploitation trivially accessible. Secured deployments require the SystemPrivilege.CreateInstances privilege to exploit. The vulnerability affects the instance management API endpoints and the underlying YAML templating engine. Fixes are available in Yamcs versions 5.12.8 and 5.13.2. Organizations running Yamcs in mission-critical or space/aerospace environments should prioritize patching immediately.
Technical details
Mitigation steps:
Affected products:
Yamcs mission control framework (prior to 5.12.8 and 5.13.2)
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-55559
https://github.com/yamcs/yamcs/commit/549f295cf8c5496a5e799d6bec2432ef976c82aa
https://github.com/yamcs/yamcs/commit/7192da1c49bdf5ab1d72e579a47766a7c43e87c8
https://github.com/yamcs/yamcs/releases/tag/yamcs-5.12.8
https://github.com/yamcs/yamcs/releases/tag/yamcs-5.13.2
https://github.com/yamcs/yamcs/security/advisories/GHSA-73mf-m39p-wpm9
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
