criticalCVE-2026-44632

CVE-2026-44632 yamcs vulnerability

Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs algorithm evaluation engine org.yamcs.algorithms.JavaExprAlgorithmExecutionFactory, which dynamically compiled and evaluated user-controlled algorithm text through the Janino compiler without enforcing a secure sandbox, so an authenticated user with the ChangeMissionDatabase privilege could override an existing algorithm's text via the mission database REST API and inject Java code (for example using java.lang.Runtime) to achieve remote code execution on the underlying host operating system. This issue is fixed in versions 5.12.7 and 5.13.0, which disable algorithm editing by default.

Browse Java security risks
Productyamcs
CVSS9.1
EPSS0.0094
UpdatedJuly 18, 2026

Quick answer

spaceapplications yamcs should be reviewed and updated if it matches the affected versions. The recommended fix is to apply the vendor-supported patched version or the mitigation steps below, then retest the public website with Fixnx.

Who is affected

Affected versions

  • Review vendor advisory for affected versions.

Fixed versions

  • Apply the latest vendor-supported patched version.

How to fix it

CVE-2026-44632 affects Yamcs before 5.12.7 and 5.13.0. A user with mission database edit rights could inject Java code through algorithm text. Upgrade Yamcs and disable unsafe algorithm editing.

  1. Upgrade Yamcs to 5.12.7, 5.13.0, or a newer fixed version for CVE-2026-44632.
  2. Keep algorithm editing disabled unless there is a clear operational need.
  3. Limit ChangeMissionDatabase permission to a very small trusted admin group.
  4. Review recently changed algorithms for unexpected Java code or Runtime usage.
  5. Check host logs for unusual processes launched by the Yamcs service account.

Scan now. Google sign-in is only needed to unlock fix guidance.

Verify the fix

  • Confirm Yamcs reports a fixed version and algorithm editing is disabled by default.
  • Test in staging that unauthorized algorithm changes are rejected.
  • Review mission database audit history for suspicious algorithm edits.

Related categories

Related security risks

More published guidance from the same primary category.

Trusted references

FAQ

What is affected by CVE-2026-44632?

spaceapplications yamcs should be checked against the vendor advisory and trusted references linked on this page.

What should I fix first?

Start with internet-facing sites, admin panels, login flows, plugins, themes, modules, packages, and systems that process user-controlled input or sensitive data.

How do I confirm the fix worked?

Apply the patched version or mitigation, clear caches where relevant, retest the affected workflow, and run a new Fixnx scan to verify public website exposure signals.

How are Fixnx security risk categories chosen?

Fixnx keeps one canonical risk page and assigns only broad, relevant categories such as ecosystem, technology area, or vulnerability class.