← Back to CVE List
CVE-2026-62329NVD
Vulnerability Summary
Vulnerability Type: CWE-1392: Use of Default Credentials Attack type: Unauthenticated remote Impact: Unauthenticated users can access the default admin account with superuser privileges. This can lead to complete compromise of IAM controls and administrative functionality. Affected components: SecurityStore.java:171-180 Yamcs creates a built-in administrative account with hardcoded credentials admin:admin during startup when the internal directory is empty, even if external authentication providers are configured. This introduces a default-credential backdoor path that can allow unauthorized administrative access. During initialization, the security store checks whether the internal directory has users and, if empty, unconditionally creates a default admin user. This occurs before external auth modules are loaded and used for authentication flow, so external provider presence does not prevent creation of the default local admin bootstrap account. Steps to Reproduce: 1. Start a Yamcs instance. 2. Navigate to http://localhost:8090/ 3. Login using the admin:admin credentials. <img width="899" height="527" alt="image" src="https://github.com/user-attachments/assets/a97e11fb-b0c9-42bd-882d-cea793a4fb85" /> 4. Result: Logged in as admin with superuser privileges. <img width="899" height="471" alt="image" src="https://github.com/user-attachments/assets/dd2dfef8-7895-4c03-82b1-37048b39bba4" /> Recommendations: 1. Remove auto-created default credentials from production paths. 2. Require explicit first-run bootstrap with a randomized one-time secret or forced password setup. 3. Gate bootstrap creation behind a dedicated secure configuration flag disabled by default. 4. Refuse startup (or warn loudly and block remote login) if default credentials are still active.
CVSS v3.1 Base Metrics — Score 9.8
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- org.yamcs:yamcs-core < 5.13.6
- org.yamcs:yamcs-core 5.13.6