Spaceapplications maintains a narrow portfolio of mission-control and command-and-telemetry software (YAMCS and YACMS) that serves space and aerospace operations, a specialized but security-critical application domain. Its vulnerabilities skew toward serious severity outcomes and cluster around web-layer input-handling and access-control weaknesses including cross-site scripting, path traversal, and UI-framing flaws that are characteristic of web applications exposed to mission planning and spacecraft command interfaces. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Spaceapplications over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-44596CRITICAL Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandl | Jul 16, 2026 | 9.8 | 50 | NO | YES |
CVE-2026-46562CRITICAL Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-core/src/main/java/org/yamcs/algor | Jul 16, 2026 | 9.8 | 40 | NO | NO |
CVE-2026-46621CRITICAL Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamically compiled and evaluated user-controlled algorithm text us | Jul 16, 2026 | 9.1 | 38 | NO | NO |
CVE-2026-44632CRITICAL Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs algorithm evaluation engine org.yamcs.algorithms.JavaExprAlgo | Jul 16, 2026 | 9.1 | 38 | NO | NO |
CVE-2026-44595MEDIUM Yamcs is a mission control framework. Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGroup in yamcs-core did not enforce the required SystemPrivilege | Jul 16, 2026 | 4.3 | 32 | NO | YES |
CVE-2023-45278CRITICAL Directory Traversal vulnerability in the storage functionality of the API in Yamcs 5.8.6 allows attackers to delete arbitrary files via crafted HTTP DELETE request. | Oct 19, 2023 | 9.1 | 25 | NO | NO |
CVE-2026-55548MEDIUM Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, the PacketsApi.exportPackets endpoint in yamcs-core/src/main/java/org/yamcs/http/api/PacketsApi.java failed to enf | Jul 16, 2026 | 4.3 | 22 | NO | NO |
CVE-2023-45277HIGH Yamcs 5.8.6 is vulnerable to directory traversal (issue 1 of 2). The vulnerability is in the storage functionality of the API and allows one to escape the base directory of the buc | Oct 19, 2023 | 7.5 | 22 | NO | NO |
CVE-2023-47311MEDIUM An issue in Yamcs 5.8.6 allows attackers to send aribitrary telelcommands in a Command Stack via Clickjacking. | Nov 20, 2023 | 6.1 | 20 | NO | NO |
CVE-2023-46471MEDIUM Cross Site Scripting vulnerability in Space Applications Services Yamcs v.5.8.6 allows a remote attacker to execute arbitrary code via the text variable scriptContainer of the Scri | Nov 20, 2023 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Spaceapplications.
Media articles that mention a CVE ID that affects a product developed by Spaceapplications — matched by CVE ID, not by vendor name.