Yamcs <=5.11.12 - Arbitrary File Read
CVE-2026-55552
Verified
Description
Yamcs through 5.11.12 serves static web resources through a handler that resolves the requested path against the configured web root without rejecting absolute paths. A request path that begins with a double slash is resolved as an absolute filesystem path, discarding the web root, and the handler returns the referenced file from the underlying host, letting unauthenticated attackers read any non-hidden file readable by the Yamcs service account whose path contains no dot segment.
Severity
High
CVSS Score
7.5
Exploit Probability
1%
Affected Product
yamcs
Published Date
October 5, 2026
Template Author
aryu-ru, abdrrahimdahmani
CVE-2026-55552.yaml
7.5Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2026-55552
CWE ID:
cwe-22
References
https://github.com/yamcs/yamcs/security/advisories/GHSA-9jg3-g3wh-w9pjhttps://github.com/yamcs/yamcs/commit/f4bc588880c166849e983aa8f65b9c8107d06091https://github.com/yamcs/yamcs/commit/c7dfd24e469ae1086c23e0fe04401cb1ce4260d4https://github.com/yamcs/yamcs/releases/tag/yamcs-5.11.13https://nvd.nist.gov/vuln/detail/CVE-2026-55552
Remediation Steps
Update to version 5.11.13, or 5.12.0 or later, which constrain resolved static file paths to the configured static roots.