CVE-2026-46562 Security Alert: CRITICAL Vulnerability
Urgent: CVE-2026-46562 requires immediate attention.
· 7 min read
Executive Summary
CVE-2026-46562 is a critical remote code execution flaw in org.yamcs:yamcs-core (CVSS 9.8). Yamcs evaluates user-supplied mission database algorithm text with Nashorn ScriptEngine but does not supply a ClassFilter. That means attacker-controlled JavaScript can reach arbitrary Java classes and execute OS commands on the Yamcs server.
This is especially urgent for solo developers and small teams because the default Yamcs setup is exposed: if security.yaml is absent, the built-in guest user has superuser=true, making the bug reachable without authentication. No exploitation in the wild is known yet, and it is not in CISA KEV, but the impact is full server compromise.
Immediate Action
- Isolate the Yamcs HTTP API from the internet now. Restrict port
8090at the firewall, security group, or reverse proxy until patched. - Upgrade immediately to a vendor-fixed release as soon as one is available. TODO: check the Yamcs advisory page / release notes for the first patched version.
- If you cannot patch today, disable access to the algorithm override endpoint and remove any users with
ChangeMissionDatabaseprivilege. - Do not rely on “guest” being harmless; in default deployments it is effectively privileged.
- Assume compromise if the service was reachable by untrusted users. Review host logs, process activity, and outbound connections.
- Vendor advisory: Yamcs security advisory / release notes
Affected Versions
org.yamcs:yamcs-core4.7.3 through 5.12.6 are vulnerable.- Current master is also vulnerable at the time of writing.
- No safe version is confirmed yet in the supplied context. TODO: upgrade to the first release that explicitly states a
ClassFilterfix. - If you maintain a fork, treat all releases since 2018-11-22 as affected until you verify a fix in code.
Resolution Guide
Java / Maven
# Find the installed version
mvn -q dependency:tree | grep yamcs-core
# Upgrade once a fixed version is known
# TODO: replace X.Y.Z with the patched release
mvn versions:use-dep-version -Dincludes=org.yamcs:yamcs-core -DdepVersion=X.Y.Z -DforceVersion=true
mvn -U clean test
Gradle
./gradlew dependencies | grep yamcs-core
# In build.gradle / build.gradle.kts, pin the fixed version:
implementation("org.yamcs:yamcs-core:X.Y.Z")
Docker
# Check the image tag you run
docker ps --format 'table {{.Image}}\t{{.Names}}'
# Replace with a patched image tag
docker pull yamcs/yamcs:X.Y.Z
docker stop yamcs
docker rm yamcs
docker run -d --name yamcs -p 8090:8090 yamcs/yamcs:X.Y.Z
Linux package managers
# apt/yum are only relevant if you installed Yamcs that way in your environment.
# TODO: replace package name/version with your distro’s Yamcs package.
apt-cache policy yamcs
yum info yamcs
Hardening until patched
# Block the API at the host firewall
ufw deny 8090/tcp
# Or restrict to a trusted admin subnet
iptables -A INPUT -p tcp --dport 8090 -s 10.0.0.0/24 -j ACCEPT
iptables -A INPUT -p tcp --dport 8090 -j DROP
Config guidance
# security.yaml: do not leave default guest superuser access enabled
# TODO: define explicit users/roles and remove broad privileges
# Example concept:
# guest:
# superuser: false
# privileges: []
Minimal code fix
// Before: no ClassFilter
scriptEngine = factory.getScriptEngine();
// After: restrict Java access
ClassFilter filter = className -> false; // or allowlist only what is required
scriptEngine = ((NashornScriptEngineFactory) factory).getScriptEngine(filter);
Detection & Verification
Check your version
java -jar yamcs.jar --version
# or inspect your dependency lockfile / container tag / package manifest
Find the vulnerable code path
grep -R "getScriptEngine()" yamcs-core/src/main/java/org/yamcs/algorithms/
grep -R "scriptEngine.eval(functionScript)" yamcs-core/src/main/java/org/yamcs/algorithms/
Confirm exposure
# If security.yaml is missing, treat the deployment as exposed by default.
ls -l security.yaml
# Check whether any user has ChangeMissionDatabase
# TODO: use your Yamcs admin/API tooling to list privileges
Verify the fix
# After upgrading, confirm the engine is created with a ClassFilter
grep -R "getScriptEngine(.*ClassFilter" yamcs-core/src/main/java/
# Confirm the endpoint no longer accepts arbitrary Java access
# A payload using Java.type(...) should fail or be blocked after the fix.
Risk and Impact
Successful exploitation gives an attacker arbitrary code execution as the Yamcs OS user. That can expose credentials, configuration, mission database content, and any files the service can read. In a ground-station environment, the blast radius can extend to telecommands, alarms, telemetry archives, and other internal systems reachable from the server.
For small teams, the practical risk is simple: if Yamcs is reachable and unpatched, treat it as a high-priority incident. Restrict access first, then patch, then review for signs of unauthorized execution.