THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-3g44-3m7x-cgg2 (critical) — Yamcs vulnerable to authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs `executeSql`

[GHSA] GHSA-3g44-3m7x-cgg2 (critical) — Yamcs vulnerable to authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs `executeSql`

highgithub_advisoriesPublished 2026-08-28

GHSA-3g44-3m7x-cgg2 Severity: critical CVE: CVE-2026-55511

Yamcs vulnerable to authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs `executeSql`

## Overview

Yamcs compiles StreamSQL expressions to Java on the fly with the Janino `SimpleCompiler` (no restrictive class-loading policy or expression sandbox). When a StreamSQL aggregate such as `sum(...)` is applied to a

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-3g44-3m7x-cgg2