PT-2026-36878 · Unknown · Openc3 Cosmos

Ctrlsill

·

Published

2026-04-22

·

Updated

2026-05-08

·

CVE-2026-42084

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenC3 COSMOS versions prior to 6.10.5 OpenC3 COSMOS versions prior to 7.0.0-rc3
Description The password change functionality allows a user to change their password without providing the current password, as the system accepts a valid session token instead. In a breach scenario, an attacker with a valid session token can exploit this to maintain persistence in a hijacked account, including administrative accounts, and block legitimate users from accessing the account.
Recommendations Update to version 6.10.5. Update to version 7.0.0-rc3.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-42084
GHSA-WGX6-G857-JJF7

Affected Products

Openc3 Cosmos