THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-9jg3-g3wh-w9pj (high) — Yamcs has Unauthenticated Directory Traversal

[GHSA] GHSA-9jg3-g3wh-w9pj (high) — Yamcs has Unauthenticated Directory Traversal

medgithub_advisoriesPublished 2026-08-28

GHSA-9jg3-g3wh-w9pj Severity: high CVE: CVE-2026-55552

Yamcs has Unauthenticated Directory Traversal

### Attack type:  Unauthenticated remote 

### Impact: Attackers can access any system files from the underlying host.

### Affected components: HttpRequestHandler.java, StaticFileHandler.java

An Unauthenticated Directory Traversal vulnerability exists in Yamcs <=5.8.6, allowing anyone to acce

Indicators of compromise

Original source: https://github.com/advisories/GHSA-9jg3-g3wh-w9pj