<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 17:37:41 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-361446</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-361446</link>
      <description>EUVD-2026-361446</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-361446</guid>
    </item>
    <item>
      <title>fkie_cve-2026-55521</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55521</link>
      <description>&lt;p&gt;Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits authorization checks in IndexesApi.listPacketIndex, IndexesApi.listEventIndex, Cop1Api.disable, Cop1Api.resume, Cop1Api.initialize, Cop1Api.updateConfig, and TimeApi.setTime. An authenticated low-privilege user can read packet and event index metadata without ObjectPrivilegeType.ReadPacket, alter COP-1 link state without SystemPrivilege.ControlLinks, and manipulate simulation time. These operations can disclose telemetry metadata, disrupt telecommand handling, and affect system integrity and availability. This issue is fixed in versions 5.12.8 and 5.13.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits authorization checks in IndexesApi.listPacketIndex, IndexesApi.listEventIndex, Cop1Api.disable, Cop1Api.resume, Cop1Api.initialize, Cop1Api.updateConfig, and TimeApi.setTime. An authenticated low-privilege user can read packet and event index metadata without ObjectPrivilegeType.ReadPacket, alter COP-1 link state without SystemPrivilege.ControlLinks, and manipulate simulation time. These operations can disclose telemetry metadata, disrupt telecommand handling, and affect system integrity and availability. This issue is fixed in versions 5.12.8 and 5.13.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-55521</guid>
    </item>
    <item>
      <title>GHSA-962x-ccwf-8x6p — Yamcs Core API has Multiple Missing Function Level Access Control vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-962x-ccwf-8x6p</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.yamcs:yamcs-core&lt;/p&gt;
&lt;p&gt;### Summary
Multiple Missing Function Level Access Control vulnerabilities exist in the Yamcs Core API. These vulnerabilities allow any authenticated user, regardless of their assigned roles or privileges (e.g., an unprivileged &amp;#34;Guest&amp;#34;), to bypass intended access controls. An attacker can exploit these flaws to extract sensitive telemetry metadata, disrupt satellite communication link protocols (COP-1), and manipulate the global simulation time, severely impacting the confidentiality, integrity, and availability of the system.&lt;/p&gt;
&lt;p&gt;### Details
Yamcs utilizes a robust Role-Based Access Control (RBAC) model with `SystemPrivilege` and `ObjectPrivilege` to restrict administrative actions and data retrieval. However, three critical API controllers completely omit these authorization checks before executing internal business logic:&lt;/p&gt;
&lt;p&gt;1.  **`IndexesApi.java` (Information Disclosure):** Unlike `PacketsApi.java`, which filters results using `ctx.user.hasObjectPrivilege(ObjectPrivilegeType.ReadPacket, packetName)`, methods in `IndexesApi` (such as `listPacketIndex` and `listEventIndex`) directly retrieve and return archive records from the `CcsdsTmIndex` without verifying if the user has the required Object Privileges.
2.  **`Cop1Api.java` (Denial of Service / Integrity):** Modifying the COP-1 telecommand protocol state is an administrative action requiring `SystemPrivilege.ControlLinks`. However, endpoints in `Cop1Api` (e.g., `disable`, `resume`, `initialize`, `updateConfig`) process link…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.yamcs:yamcs-core&lt;/p&gt;
&lt;p&gt;### Summary
Multiple Missing Function Level Access Control vulnerabilities exist in the Yamcs Core API. These vulnerabilities allow any authenticated user, regardless of their assigned roles or privileges (e.g., an unprivileged &amp;#34;Guest&amp;#34;), to bypass intended access controls. An attacker can exploit these flaws to extract sensitive telemetry metadata, disrupt satellite communication link protocols (COP-1), and manipulate the global simulation time, severely impacting the confidentiality, integrity, and availability of the system.&lt;/p&gt;
&lt;p&gt;### Details
Yamcs utilizes a robust Role-Based Access Control (RBAC) model with `SystemPrivilege` and `ObjectPrivilege` to restrict administrative actions and data retrieval. However, three critical API controllers completely omit these authorization checks before executing internal business logic:&lt;/p&gt;
&lt;p&gt;1.  **`IndexesApi.java` (Information Disclosure):** Unlike `PacketsApi.java`, which filters results using `ctx.user.hasObjectPrivilege(ObjectPrivilegeType.ReadPacket, packetName)`, methods in `IndexesApi` (such as `listPacketIndex` and `listEventIndex`) directly retrieve and return archive records from the `CcsdsTmIndex` without verifying if the user has the required Object Privileges.
2.  **`Cop1Api.java` (Denial of Service / Integrity):** Modifying the COP-1 telecommand protocol state is an administrative action requiring `SystemPrivilege.ControlLinks`. However, endpoints in `Cop1Api` (e.g., `disable`, `resume`, `initialize`, `updateConfig`) process link…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-962x-ccwf-8x6p</guid>
    </item>
  </channel>
</rss>
