Retour aux alertes CVE
CVE-2026-44596 MEDIUM CVSS 6.5

CVE-2026-44596 — MEDIUM

Publiée 1 month ago Fiche NVD officielle

Qu'est-ce que c'est ?

Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandler.java, lacked any rate limiting, account lockout, or failed-attempt throttling, so an unauthenticated remote attacker could perform unlimited password-guessing attempts against any user account, significantly increasing the risk of successful brute-force attacks. This issue is fixed in versions 5.12.7 and 5.13.0.

Technologies affectées

Non précisé par la fiche NVD.

Recommandation

Vérifie la disponibilité d'un correctif pour la technologie concernée et applique-le dès que possible. Consulte la fiche NVD pour les références officielles du fournisseur.

Exploits publics connus (1)

ex-cal1bur/CVE-2026-44596

YAMCS yamcs-core < 5.12.7 lacks rate limiting on POST /auth/token. An unauthenticated attacker can perform unlimited brute-force attempts ag...

Usage responsable : ces liens pointent vers des dépôts publics GitHub à but éducatif ou de test d'intrusion autorisé. N'utilise ces PoC que sur des systèmes que tu es autorisé à tester.