CVE-2026-42568
MEDIUM 4.3EPSS 1.0%
Yamcs is a mission control framework. Prior to versions 5.13.0 and 5.12.7, an LDAP injection vulnerability exists in `org.yamcs.security.LdapAuthModule` when constructing search filters. The username parameter is inserted directly into the LDAP filter without proper RFC 4515 escaping. Versions 5.13.0 and 5.12.7 patch the issue.
- CVSS v3.1
- 4.3 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N - CVSS v3.1
- 4.3 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N - EPSS
- 1.03% chance of exploitation in the next 30 days, 61th percentile
- Published
- 2026-06-10
- Updated
- 2026-06-11
Proof-of-concept exploits (2)
- advisories/GHSA-cqh3-jg8p-336j
- ex-cal1bur/CVE-2026-425680★ · 2026-05-29