THREAT OPS › Threat News › [GHSA] GHSA-3g44-3m7x-cgg2 (critical) — Yamcs vulnerable to authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs `executeSql`
[GHSA] GHSA-3g44-3m7x-cgg2 (critical) — Yamcs vulnerable to authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs `executeSql`
GHSA-3g44-3m7x-cgg2 Severity: critical CVE: CVE-2026-55511
Yamcs vulnerable to authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs `executeSql`
## Overview
Yamcs compiles StreamSQL expressions to Java on the fly with the Janino `SimpleCompiler` (no restrictive class-loading policy or expression sandbox). When a StreamSQL aggregate such as `sum(...)` is applied to a
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- 8bf5af6fe227bbf8ead15e60644b7ddbf345d623sha1
- CVE-2026-55511cve
- CVE-2026-44632cve
- java.iodomain
Original source: https://github.com/advisories/GHSA-3g44-3m7x-cgg2