THREAT OPS › Threat News › [GHSA] GHSA-cvw4-55pp-3hfq (medium) — Yamcs's Missing Authorization on Role and Privilege Enumeration Endpoints Allows Any Authenticated User to Disclose Full Security Configuration
[GHSA] GHSA-cvw4-55pp-3hfq (medium) — Yamcs's Missing Authorization on Role and Privilege Enumeration Endpoints Allows Any Authenticated User to Disclose Full Security Configuration
GHSA-cvw4-55pp-3hfq Severity: medium CVE: CVE-2026-55547
Yamcs's Missing Authorization on Role and Privilege Enumeration Endpoints Allows Any Authenticated User to Disclose Full Security Configuration
## Summary
Missing authorization checks on three IAM API endpoints (`GET /api/roles`, `GET /api/roles/{name}`, `GET /api/privileges`) allow any authenticated user — regardless of their assigned pe
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-55547cve
Original source: https://github.com/advisories/GHSA-cvw4-55pp-3hfq