Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-44596

50
FAUCET Score

Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandler.java, lacked any rate limiting, account lockout, or failed-attempt throttling, so an unauthenticated remote attacker could perform unlimited password-guessing attempts against any user account, significantly increasing the risk of successful brute-force attacks. This issue is fixed in versions 5.12.7 and 5.13.0.

First published: Jul 16, 2026Last modified: Jul 16, 2026

Impacted Technologies

VendorProductVersion(s)CPE
< 5.12.7CPE matchmatch criteria
cpe:2.3:a:spaceapplications:yamcs:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
2.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.73%
Probability of exploitation in next 30 days
EPSS Percentile
75.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
ExploitDB: EDB-52605 · May 30, 2026
This CVE's current EPSS score of 0.0173 is in the 63rd percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
mavenpatch availablevia ghsa
Product: org.yamcs:yamcs-coreFixed in: 5.12.7

Vendor Advisories (1)

mavenGHSA-w5r6-mcgq-7pq4medium

Yamcs has No Rate Limiting on Authentication Endpoint

May 27, 2026

References

github.com / yamcs/yamcs/commit/309218c651680f79df11a8d0f8628f7033f98a83
Patch
github.com / yamcs/yamcs/commit/64392df531fbcbc65f19ee5724c4c23d289f49fc
Patch
github.com / yamcs/yamcs/releases/tag/yamcs-5.12.7
Release Notes
github.com / yamcs/yamcs/releases/tag/yamcs-5.13.0
Release Notes
github.com / yamcs/yamcs/security/advisories/GHSA-w5r6-mcgq-7pq4
ExploitVendor Advisory