Spaceapplications Yamcs — CVE-2026-44596 (Critical)

Date Jul 16, 2026
Type Vendor advisory
Signal Critical vendor advisory
Vendor / Product Spaceapplications · Yamcs
CVE CVE-2026-44596
Critical vendor advisory CVE-2026-44596

Summary

Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandler.java, lacked any rate limiting, account lockout, or failed-attempt throttling, so an unauthenticated remote attacker could perform unlimited password-guessing attempts against any user account, significantly increasing the risk of successful brute-force attacks. This issue is fixed in versions 5.12.7 and 5.13.0.

Why it matters

This CVE carries a CRITICAL severity rating (CVSS 6.5) in Spaceapplications Yamcs. Patch or mitigate promptly. EPSS percentile: 69%.

Operator check

Review CVE-2026-44596 in your asset inventory. Apply patches per vendor guidance and verify Yamcs is not exposed. CVSS score: 6.5. EPSS probability: 1.4%; percentile: 69%.

Sources

PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.