THREAT OPS › Threat News › [GHSA] GHSA-fwww-cp23-7f5g (medium) — Yamcs's WebSocket subscription handlers omit the privilege checks their REST siblings enforce
[GHSA] GHSA-fwww-cp23-7f5g (medium) — Yamcs's WebSocket subscription handlers omit the privilege checks their REST siblings enforce
GHSA-fwww-cp23-7f5g Severity: medium CVE: CVE-2026-55545
Yamcs's WebSocket subscription handlers omit the privilege checks their REST siblings enforce
**Asset / scope:** Yamcs 5.12.7 WebSocket topics (`packets`, `algorithm-status`, `mdb-changes`)
## Summary
Several WebSocket subscription handlers do not perform the privilege check that their REST counterparts enforce, so a principal subscribin
Indicators of compromise
- CVE-2026-55545cve
- https://causalsecurity.com/url
Original source: https://github.com/advisories/GHSA-fwww-cp23-7f5g