MEDIUM 4.3 GitHub
CVE-2026-55548
Yamcs: Insecure Direct Object Reference (IDOR) in PacketsApi allows unprivileged users to dump all telemetry packets
## Summary
The `PacketsApi.exportPackets` endpoint in Yamcs fails to properly enforce object-level privileges (`ReadPacket`) when an API request omits specific packet names. As a result, an attacker with a low-privileged account (or any authenticated user with zero privileges) can dump the entire archive of raw telemetry packets for a Yamcs instance. This leads to a massive Information Disclosure of sensitive mission telemetry, completely bypassing the intended Role-Based Access Control (RBAC) m
Affected Products
- maven/org.yamcs:yamcs-core >= 5.13.0, <= 5.13.1
- maven/org.yamcs:yamcs-core <= 5.12.7
References
- https://github.com/advisories/GHSA-8xjq-pr36-ccgf
- https://github.com/yamcs/yamcs/security/advisories/GHSA-8xjq-pr36-ccgf
- https://nvd.nist.gov/vuln/detail/CVE-2026-55548
- https://github.com/yamcs/yamcs/commit/b566beceba98cc35514b0e1519be126b8c5a0438
This medium severity vulnerability with a CVSS score of 4.3 was published on 2026-08-28 via GitHub. Affected: maven/org.yamcs:yamcs-core >= 5.13.0, <= 5.13.1, maven/org.yamcs:yamcs-core <= 5.12.7.
vulnfeed aggregates 11493 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.