{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/yamcs-core-5.13.0-5.13.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:yamcs:yamcs_core:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-55552"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["yamcs-core (\u003c 5.11.13)","yamcs-core (5.13.0-5.13.1)","yamcs-core (\u003c= 5.12.7)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","directory-traversal","cve-2026-55552","privilege-escalation","web-application-vulnerability"],"_cs_type":"advisory","_cs_vendors":["Yamcs"],"content_html":"\u003cp\u003eYamcs versions prior to 5.11.13 are susceptible to an unauthenticated directory traversal vulnerability (CVE-2026-55552) residing in the \u003ccode\u003eHttpRequestHandler.java\u003c/code\u003e and \u003ccode\u003eStaticFileHandler.java\u003c/code\u003e components. This flaw allows remote, unauthenticated attackers to bypass intended directory restrictions by crafting specific HTTP requests containing traversal sequences. An attacker can leverage this to retrieve sensitive system files, configuration files, or other data residing on the host filesystem where Yamcs is deployed. Given the nature of the application as a mission control system, exposure of sensitive configuration or authentication files poses a significant risk to the integrity and confidentiality of the entire environment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation grants an unauthenticated attacker the ability to read arbitrary files from the filesystem of the host running the Yamcs service. This can lead to the exfiltration of credentials, system configuration details, or sensitive operational data, potentially facilitating further unauthorized access or complete system compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade Yamcs to version 5.11.13 or later immediately to patch CVE-2026-55552.\u003c/li\u003e\n\u003cli\u003eImplement network-level access controls to restrict access to the Yamcs management interface to known, trusted IP ranges.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to web server access logs to detect directory traversal attempts.\u003c/li\u003e\n\u003cli\u003ePerform a log review for any historical GET requests to the Yamcs interface containing '..' or unusual path indicators.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-28T21:18:40Z","date_published":"2026-08-28T21:18:21Z","id":"https://feed.craftedsignal.io/briefs/2026-08-yamcs-traversal/","summary":"Yamcs versions prior to 5.11.13 contain an unauthenticated directory traversal vulnerability in the HTTP request handling components that allows remote attackers to read arbitrary files from the underlying host.","title":"Unauthenticated Directory Traversal in Yamcs","url":"https://feed.craftedsignal.io/briefs/2026-08-yamcs-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Yamcs-Core (5.13.0-5.13.1)","version":"https://jsonfeed.org/version/1.1"}