4.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Description
Yamcs is a mission control framework. Prior to versions 5.13.0 and 5.12.7, an LDAP injection vulnerability exists in `org.yamcs.security.LdapAuthModule` when constructing search filters. The username parameter is inserted directly into the LDAP filter without proper RFC 4515 escaping. Versions 5.13.0 and 5.12.7 patch the issue.
Basic Information
ID
CVE-2026-42568
Source
GitHub_M
Published
Jun 10, 2026 at 22:15
Affected Product
Vendor
yamcs
Product
yamcs
Version
< 5.12.7
Affected Versions
yamcs yamcs < 5.12.7