CVE-2026-44596: Yamcs: No Rate Limiting on Authentication Endpoint
Summary
The authentication endpoint POST /auth/token in yamcs-core lacks any form of rate limiting, account lockout, or failed attempt throttling. As a result, an unauthenticated remote attacker can perform unlimited password guessing attempts against any user account.
This missing rate limiting vulnerability (CWE-307) significantly increases the risk of successful brute-force attacks.
Root Cause
File: yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandler.java
POST /auth/token has no rate limiting, no lockout after failed attempts, and no CAPTCHA. The handler processes unlimited authentication requests without any throttling mechanism:
java // AuthHandler.java — handleToken() // No throttle, no failed attempt counter, no lockout private void handleToken(HandlerContext ctx) { ... getSecurityStore().login(token).whenComplete((info, err) -> { // Directly attempts authentication with no rate check }); }
This is absent by default — the official quickstart and documentation contain no guidance on configuring rate limiting.
Impact
An attacker can make unlimited authentication attempts against any account. This enables efficient brute-force attacks against any account.
Proof of Concept
bash 20 attempts — zero rate limiting for i in $(seq 1 20); do curl -s -o /dev/null -w "Attempt $i: HTTP %{httpcode}\n" \ -X POST "http://TARGET:8090/auth/token" \ -d "granttype=password&username=operator&password=operator12$i" done All return HTTP 401 — no HTTP 429 ever
Confirmed: 20 attempts in 0.07 seconds, no rate limiting enforced.
Fix
Implement DRF-style throttling on /auth/token:
java // Track failed attempts per IP private static final Cache<String, Integer> FAILEDATTEMPTS = CacheBuilder.newBuilder().expireAfterWrite(15, TimeUnit.MINUTES).build();
private static final int MAXATTEMPTS = 10;
private void handleToken(HandlerContext ctx) { String ip = ctx.getRemoteAddress(); int attempts = Optional.ofNullable(FAILEDATTEMPTS.getIfPresent(ip)).orElse(0); if (attempts >= MAXATTEMPTS) { throw new TooManyRequestsException("Rate limit exceeded"); } // ... existing auth logic // On failure: FAILEDATTEMPTS.put(ip, attempts + 1) }
Other sources
Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandler.java, lacked any rate limiting, account lockout, or failed-attempt throttling, so an unauthenticated remote attacker could perform unlimited password-guessing attempts against any user account, significantly increasing the risk of successful brute-force attacks. This issue is fixed in versions 5.12.7 and 5.13.0.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.yamcs:yamcs-coreto a version that resolves this vulnerability.Fixed in 5.12.7 - Upgrade
Upgrade
yamcs-coreto a version that resolves this vulnerability.Fixed in 5.12.7 - Upgrade
Upgrade
yamcs-coreto a version that resolves this vulnerability.Fixed in 5.13.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44596?
The severity of CVE-2026-44596 is medium with a score of 6.5.
How does CVE-2026-44596 pose a security risk?
CVE-2026-44596 allows unauthenticated remote attackers to perform unlimited password guessing attempts due to the lack of rate limiting on the authentication endpoint.
What software is affected by CVE-2026-44596?
The vulnerability CVE-2026-44596 affects the software package maven/org.yamcs:yamcs-core.
How can organizations mitigate the risk of CVE-2026-44596?
Organizations can mitigate the risk of CVE-2026-44596 by implementing rate limiting, account lockout mechanisms, and failed attempt throttling on the authentication endpoint.
When was CVE-2026-44596 published?
CVE-2026-44596 was published on May 27, 2026.