CVE-2026-42568
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/06/2026
Last modified:
11/06/2026
Description
Yamcs is a mission control framework. Prior to versions 5.13.0 and 5.12.7, an LDAP injection vulnerability exists in `org.yamcs.security.LdapAuthModule` when constructing search filters. The username parameter is inserted directly into the LDAP filter without proper RFC 4515 escaping. Versions 5.13.0 and 5.12.7 patch the issue.
Impact
Base Score 3.x
4.30
Severity 3.x
MEDIUM



