CVE-2026-77602
9.9 CRITICALpublic exploit availablePublished 2026-09-23 · Updated 2026-09-29
AI risk analysis
- Summary
- Authenticated non-administrator users can write content that is later executed with elevated privileges, leading to remote code execution.
- Exploitability
- Exploitation requires authentication and access to the targets_modified/ directory, making it moderately hard to exploit.
- Blast radius
- If exploited, the impact could be severe, as it allows execution of arbitrary code with internal credentials and data access.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to OpenC3 COSMOS version 7.3.0 or later.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.1.0 until 7.3.0, authenticated non-administrator users can write content under targets_modified/ that is later executed by multiple configuration paths below the intended code-execution privilege tier. Table and command or telemetry definitions are processed through ConfigParser, PacketConfig, GENERIC_READ_CONVERSION, or GENERIC_WRITE_CONVERSION, allowing ERB rendering or Ruby and Python evaluation, while openc3-cosmos-script-runner-api/scripts/run_suite_analysis.rb executes suite procedure files through require. Storage uploads, screen saves, and script creation can place content in the overlay, and triggering table processing, a cmd/tlm reload, or suite analysis executes the content in cmd-tlm-api, decom microservices, or Script Runner with access to internal credentials and data. This issue is fixed in version 7.3.0.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Weaknesses
CWE-94
Public exploit & PoC references
- https://github.com/OpenC3/cosmos/commit/71943352a28128ef3e7e894319d97a656b5cd4f2
- https://github.com/OpenC3/cosmos/commit/7a1538a4626f82c0d1540fcaa27ffdcbbd71ff81
- https://github.com/OpenC3/cosmos/pull/3488
- https://github.com/OpenC3/cosmos/security/advisories/GHSA-jjq7-m736-w977
- https://github.com/OpenC3/cosmos/security/advisories/GHSA-jjq7-m736-w977
All references
- https://github.com/OpenC3/cosmos/commit/71943352a28128ef3e7e894319d97a656b5cd4f2
- https://github.com/OpenC3/cosmos/commit/7a1538a4626f82c0d1540fcaa27ffdcbbd71ff81
- https://github.com/OpenC3/cosmos/pull/3488
- https://github.com/OpenC3/cosmos/security/advisories/GHSA-jjq7-m736-w977
- https://github.com/OpenC3/cosmos/security/advisories/GHSA-jjq7-m736-w977
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-19804
- HIGHCVE-2026-4327
- CRITICALCVE-2026-62104
- CRITICALCVE-2026-71278PoC
- HIGHCVE-2026-84858
- HIGHCVE-2026-92807
- CRITICALCVE-2026-93985PoC
- HIGHCVE-2025-51457
Related by shared AI tags and CWE weakness class. Browse the full archive.