CVE-2026-46562 Security Alert: CRITICAL Vulnerability

Urgent: CVE-2026-46562 requires immediate attention.

· 7 min read

Executive Summary

CVE-2026-46562 is a critical remote code execution flaw in org.yamcs:yamcs-core (CVSS 9.8). Yamcs evaluates user-supplied mission database algorithm text with Nashorn ScriptEngine but does not supply a ClassFilter. That means attacker-controlled JavaScript can reach arbitrary Java classes and execute OS commands on the Yamcs server.

This is especially urgent for solo developers and small teams because the default Yamcs setup is exposed: if security.yaml is absent, the built-in guest user has superuser=true, making the bug reachable without authentication. No exploitation in the wild is known yet, and it is not in CISA KEV, but the impact is full server compromise.

Immediate Action

  • Isolate the Yamcs HTTP API from the internet now. Restrict port 8090 at the firewall, security group, or reverse proxy until patched.
  • Upgrade immediately to a vendor-fixed release as soon as one is available. TODO: check the Yamcs advisory page / release notes for the first patched version.
  • If you cannot patch today, disable access to the algorithm override endpoint and remove any users with ChangeMissionDatabase privilege.
  • Do not rely on “guest” being harmless; in default deployments it is effectively privileged.
  • Assume compromise if the service was reachable by untrusted users. Review host logs, process activity, and outbound connections.
  • Vendor advisory: Yamcs security advisory / release notes

Affected Versions

  • org.yamcs:yamcs-core 4.7.3 through 5.12.6 are vulnerable.
  • Current master is also vulnerable at the time of writing.
  • No safe version is confirmed yet in the supplied context. TODO: upgrade to the first release that explicitly states a ClassFilter fix.
  • If you maintain a fork, treat all releases since 2018-11-22 as affected until you verify a fix in code.

Resolution Guide

Java / Maven

# Find the installed version
mvn -q dependency:tree | grep yamcs-core

# Upgrade once a fixed version is known
# TODO: replace X.Y.Z with the patched release
mvn versions:use-dep-version -Dincludes=org.yamcs:yamcs-core -DdepVersion=X.Y.Z -DforceVersion=true
mvn -U clean test

Gradle

./gradlew dependencies | grep yamcs-core

# In build.gradle / build.gradle.kts, pin the fixed version:
implementation("org.yamcs:yamcs-core:X.Y.Z")

Docker

# Check the image tag you run
docker ps --format 'table {{.Image}}\t{{.Names}}'

# Replace with a patched image tag
docker pull yamcs/yamcs:X.Y.Z
docker stop yamcs
docker rm yamcs
docker run -d --name yamcs -p 8090:8090 yamcs/yamcs:X.Y.Z

Linux package managers

# apt/yum are only relevant if you installed Yamcs that way in your environment.
# TODO: replace package name/version with your distro’s Yamcs package.
apt-cache policy yamcs
yum info yamcs

Hardening until patched

# Block the API at the host firewall
ufw deny 8090/tcp

# Or restrict to a trusted admin subnet
iptables -A INPUT -p tcp --dport 8090 -s 10.0.0.0/24 -j ACCEPT
iptables -A INPUT -p tcp --dport 8090 -j DROP

Config guidance

# security.yaml: do not leave default guest superuser access enabled
# TODO: define explicit users/roles and remove broad privileges
# Example concept:
# guest:
#   superuser: false
#   privileges: []

Minimal code fix

// Before: no ClassFilter
scriptEngine = factory.getScriptEngine();

// After: restrict Java access
ClassFilter filter = className -> false; // or allowlist only what is required
scriptEngine = ((NashornScriptEngineFactory) factory).getScriptEngine(filter);

Detection & Verification

Check your version

java -jar yamcs.jar --version
# or inspect your dependency lockfile / container tag / package manifest

Find the vulnerable code path

grep -R "getScriptEngine()" yamcs-core/src/main/java/org/yamcs/algorithms/
grep -R "scriptEngine.eval(functionScript)" yamcs-core/src/main/java/org/yamcs/algorithms/

Confirm exposure

# If security.yaml is missing, treat the deployment as exposed by default.
ls -l security.yaml

# Check whether any user has ChangeMissionDatabase
# TODO: use your Yamcs admin/API tooling to list privileges

Verify the fix

# After upgrading, confirm the engine is created with a ClassFilter
grep -R "getScriptEngine(.*ClassFilter" yamcs-core/src/main/java/

# Confirm the endpoint no longer accepts arbitrary Java access
# A payload using Java.type(...) should fail or be blocked after the fix.

Risk and Impact

Successful exploitation gives an attacker arbitrary code execution as the Yamcs OS user. That can expose credentials, configuration, mission database content, and any files the service can read. In a ground-station environment, the blast radius can extend to telecommands, alarms, telemetry archives, and other internal systems reachable from the server.

For small teams, the practical risk is simple: if Yamcs is reachable and unpatched, treat it as a high-priority incident. Restrict access first, then patch, then review for signs of unauthorized execution.

Keep reading