CVE-2026-42568 is an LDAP injection vulnerability in Yamcs affecting versions prior to 5.13.0 and 5.12.7. The flaw is in org.yamcs.security.LdapAuthModule, where the username parameter is incorporated directly into an LDAP search filter without proper escaping per RFC 4515. Because attacker-controlled input is used in filter construction, a crafted username containing LDAP metacharacters can alter the intended query semantics. The provided advisory specifically notes that a username such as * can manipulate the LDAP search behavior during authentication.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
* and authenticate as the first user returned by the LDAP search. This results in horizontal privilege escalation between accounts in deployments that use LdapAuthModule. Impact is therefore unauthorized account access and any permissions or data available to the impersonated user.If you can’t patch tonight, do this now.
org.yamcs.security.LdapAuthModule where operationally feasible, reduce exposure of the /auth/token endpoint, and enforce strict validation or RFC 4515-compliant escaping of usernames before they are used in LDAP search filters. Monitor authentication logs for suspicious usernames containing wildcard or other LDAP filter metacharacters.Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Small standalone repository containing a README and a single Python PoC script for CVE-2026-42568, an LDAP injection vulnerability in YAMCS LdapAuthModule. The exploit targets yamcs-core versions prior to 5.12.7 when LDAP authentication is enabled. The script uses Python requests to send POST requests to the YAMCS password-grant authentication endpoint /auth/token, supplying crafted username values that break or broaden the LDAP search filter. Three built-in payload strategies are included: a universal bypass intended to match any account, a targeted bypass aimed at an admin-like account, and a wildcard enumeration-style username. The script reports HTTP status codes, distinguishes likely vulnerable vs. patched/non-LDAP cases, and on HTTP 200 attempts to parse and print an access token from the JSON response. Repository purpose is clearly exploit demonstration and validation of authentication bypass, not merely documentation or passive detection.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.