CVE-2026-42568

Yamcs is a mission control framework. Prior to versions 5.13.0 and 5.12.7, an LDAP injection vulnerability exists in `org.yamcs.security.LdapAuthModule` when constructing search filters. The username parameter is inserted directly into the LDAP filter without proper RFC 4515 escaping. Versions 5.13.0 and 5.12.7 patch the issue.
Configurations

No configuration.

History

21 Jul 2026, 19:10

Type Values Removed Values Added
Summary
  • (es) Yamcs es un framework de control de misión. Antes de las versiones 5.13.0 y 5.12.7, existe una vulnerabilidad de inyección LDAP en 'org.yamcs.security.LdapAuthModule' al construir filtros de búsqueda. El parámetro de nombre de usuario se inserta directamente en el filtro LDAP sin el escape RFC 4515 adecuado. Las versiones 5.13.0 y 5.12.7 parchean el problema.

10 Jun 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-10 23:16

Updated : 2026-07-21 19:10


NVD link : CVE-2026-42568

Mitre link : CVE-2026-42568

CVE.ORG link : CVE-2026-42568


JSON object : View

Products Affected

No product.

CWE
CWE-90

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')