Yamcs is a mission control framework. Prior to versions 5.13.0 and 5.12.7, an LDAP injection vulnerability exists in `org.yamcs.security.LdapAuthModule` when constructing search filters. The username parameter is inserted directly into the LDAP filter without proper RFC 4515 escaping. Versions 5.13.0 and 5.12.7 patch the issue.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-06-10 23:16
Updated : 2026-07-21 19:10
NVD link : CVE-2026-42568
Mitre link : CVE-2026-42568
CVE.ORG link : CVE-2026-42568
JSON object : View
Products Affected
No product.
CWE
CWE-90
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
