Yamcs is a mission control framework. Prior to versions 5.13.0 and 5.12.7, an LDAP injection vulnerability exists in `org.yamcs.security.LdapAuthModule` when constructing search filters. The username parameter is inserted directly into the LDAP filter without proper RFC 4515 escaping. Versions 5.13.0 and 5.12.7 patch the issue.
References
Configurations
No configuration.
History
21 Jul 2026, 19:10
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
10 Jun 2026, 23:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-10 23:16
Updated : 2026-07-21 19:10
NVD link : CVE-2026-42568
Mitre link : CVE-2026-42568
CVE.ORG link : CVE-2026-42568
JSON object : View
Products Affected
No product.
CWE
CWE-90
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
