CVE-2026-42568
Yamcs is a mission control framework. Prior to versions 5.13.0 and 5.12.7, an LDAP injection vulnerability exists in `org.yamcs.security.LdapAuthModule` when constructing search filters. The username parameter is inserted directly into the LDAP filter without proper RFC 4515 escaping. Versions 5.13.0 and 5.12.7 patch the issue.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS probability
- 1.03%
- CWE
- CWE-90
- Published
- 2026-06-10
- Last modified
- 2026-06-11
Affected products
- yamcs yamcs
Weakness type
Related vulnerabilities
- CVE-2026-80055 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-78579 — Improper Input Sanitization in Okta Access Gateway LDAP Datastore Filter Interpolation
- CVE-2026-81205 — LDAP / Active Directory Integration - Moderately critical - Information Disclosure - SA-CONTRIB-2026-115
- CVE-2026-75020 — Apache APISIX: ldap-auth plugin cross-subtree identity impersonation
- CVE-2026-19271 — Blind LDAP Injection in Sign-In Endpoint in TÜBİTAK BİLGEM's Liderahenk
- CVE-2026-76373 — Filter Injection through Action Parameters in AD LDAP app for Splunk SOAR
- CVE-2026-19930 — Dolibarr User Cloning card.php ldap injection
- CVE-2026-74241 — Quay: ldap referral filter injection in quay external ldap authentication