THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-fwww-cp23-7f5g (medium) — Yamcs's WebSocket subscription handlers omit the privilege checks their REST siblings enforce

[GHSA] GHSA-fwww-cp23-7f5g (medium) — Yamcs's WebSocket subscription handlers omit the privilege checks their REST siblings enforce

highgithub_advisoriesPublished 2026-08-28

GHSA-fwww-cp23-7f5g Severity: medium CVE: CVE-2026-55545

Yamcs's WebSocket subscription handlers omit the privilege checks their REST siblings enforce

**Asset / scope:** Yamcs 5.12.7 WebSocket topics (`packets`, `algorithm-status`, `mdb-changes`)

## Summary

Several WebSocket subscription handlers do not perform the privilege check that their REST counterparts enforce, so a principal subscribin

Indicators of compromise

Original source: https://github.com/advisories/GHSA-fwww-cp23-7f5g