CVE-2026-42088Disclosure(openc3 / cosmos)

LOWCVSS 8.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch openc3 cosmos systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-250

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cosmos

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 4 classified signals
  • Peaked 2d ago at 5 mentions (2026-05-13); latest day: 2
  • 9 total mentions across 4 days

Affected systems

Vendors
Products
cosmos

1 version affected across 1 product

Deep dive

Activity timeline9 mentions / 4d
01345Mentions · 2026-05-04: 1Mentions · 2026-05-13: 5Mentions · 2026-05-25: 1Mentions · 2026-06-03: 2Patch / Workaround · 2026-05-25: 1Technical Details · 2026-05-13: 2Technical Details · 2026-05-25: 1Technical Details · 2026-06-03: 205-0405-1305-2506-03
Signal classification3 categories
Disclosure
444.4%
General
444.4%
Patch
111.1%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-041
Disclosure1
2026-05-135
Disclosure1General4
2026-05-251
Patch1
2026-06-032
Disclosure2
Full discourse9 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-42088 (Authorization Bypass): The Script Runner widget allows authenticated users to execute Python and Ruby scripts within the COSMOS Docker environment. Those scripts can reach any service on the internal Docker network, including the Redis database and the…

    Post summary

    The entry discloses that CVE‑2026‑42088 allows authenticated users to run arbitrary Python and Ruby scripts in the COSMOS Docker environment, giving them unrestricted access to internal services such as Redis.

    1001035
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    TL;DR OpenC3 COSMOS, the command-and-control platform for industrial SCADA systems, was disclosed on May 4, 2026 with TWO critical vulnerabilities (both CVSS 9.6). CVE-2026-42087 is an unauthenticated SQL injection in the time-series database; CVE-2026-42088 allows…

    Post summary

    The note announces the disclosure of two critical CVEs (CVE‑2026‑42087/42088) in OpenC3 COSMOS, detailing an unauthenticated SQL injection and high severity ratings, with no PoC, exploit, patch, or active‑exploitation claims.

    1000027
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    --- Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation. CVE: CVE-2026-42088 CVSS: 9.6 (3.1) — CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory

    Post summary

    The text announces CVE-2026-42088 as a critical vulnerability with a CVSS 9.6 rating, but provides no PoC, exploit, patch, or evidence of active exploitation.

    1000033
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    References CVE: CVE-2026-42088 CVSS: 9.6 (3.1) — CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory

    Post summary

    The text references CVE-2026-42088, providing its CVSS score and critical advisory status, but offers no further technical or operational details.

    1000029
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-42088-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided text lacks explicit details about any aspect of CVE‑2026‑42088.

    0001026
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVE: CVE-2026-42088 CVSS: 9.6 (3.1) — CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems.

    Post summary

    The post lists a critical CVE with a high CVSS score but lacks concrete details about exploitation, tooling, or mitigation.

    1000036
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CRITICAL: CVE-2026-42088 (CVSS 9.6) — multiple products. CVE: CVE-2026-42088 CVSS: 9.6 (3.1) — CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory

    Post summary

    The text provides basic details about CVE-2026-42088, such as its CVSS score and severity, but contains no exploitation or mitigation information.

    1000035
    210 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2026-42088 (CVSS 9.6) OpenC3 COSMOS Script Runner allows privilege escalation via crafted scripts to bypass API checks, access Redis secrets & modify settings. Patch: Upgrade to v7.0.0-rc3+ #CVE #Vulnerability #PatchNow https://t.co/Ykg47taUXv

    Post summary

    The tweet announces a critical privilege escalation vulnerability in OpenC3 COSMOS Script Runner and recommends upgrading to v7.0.0-rc3+ to mitigate it.

    0000062
    30 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42088 OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner … https://www.cve.org/CVERecord?id=CVE-2026-42088

    Post summary

    The post announces CVE‑2026‑42088 affecting OpenC3 COSMOS’ Script Runner prior to 7.0.0‑rc3, highlighting potential command handling issues on embedded systems.

    00000117
    57.4K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appopenc3cosmos---
Appopenc3cosmos7.0.0--
Appopenc3cosmos7.0.0--

Explore more