← Back to search

CVE-2026-77602

9.9 CRITICALpublic exploit available

Published 2026-09-23 · Updated 2026-09-29

AI risk analysis

Summary
Authenticated non-administrator users can write content that is later executed with elevated privileges, leading to remote code execution.
Exploitability
Exploitation requires authentication and access to the targets_modified/ directory, making it moderately hard to exploit.
Blast radius
If exploited, the impact could be severe, as it allows execution of arbitrary code with internal credentials and data access.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to OpenC3 COSMOS version 7.3.0 or later.
rceauth-bypassweb

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.1.0 until 7.3.0, authenticated non-administrator users can write content under targets_modified/ that is later executed by multiple configuration paths below the intended code-execution privilege tier. Table and command or telemetry definitions are processed through ConfigParser, PacketConfig, GENERIC_READ_CONVERSION, or GENERIC_WRITE_CONVERSION, allowing ERB rendering or Ruby and Python evaluation, while openc3-cosmos-script-runner-api/scripts/run_suite_analysis.rb executes suite procedure files through require. Storage uploads, screen saves, and script creation can place content in the overlay, and triggering table processing, a cmd/tlm reload, or suite analysis executes the content in cmd-tlm-api, decom microservices, or Script Runner with access to internal credentials and data. This issue is fixed in version 7.3.0.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-94

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.