
[CVE] CVE-2026-77602 [HIGH PRIORITY] #OpenC3 COSMOS: Authenticated remote code execution via the user-writable conf... 🔗 https://exploitgrid.net/cve/CVE-2026-77602
Signal is active with 3 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.1.0 until 7.3.0, authenticated non-administrator users can write content under targets_modified/ that is later executed by multiple configuration paths below the intended code-execution privilege tier. Table and command or telemetry definitions are processed through ConfigParser, PacketConfig, GENERIC_READ_CONVERSION, or GENERIC_WRITE_CONVERSION, allowing ERB rendering or Ruby and Python evaluation, while openc3-cosmos-script-runner-api/scripts/run_suite_analysis.rb executes suite procedure files through require. Storage uploads, screen saves, and script creation can place content in the overlay, and triggering table processing, a cmd/tlm reload, or suite analysis executes the content in cmd-tlm-api, decom microservices, or Script Runner with access to internal credentials and data. This issue is fixed in version 7.3.0.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

[CVE] CVE-2026-77602 [HIGH PRIORITY] #OpenC3 COSMOS: Authenticated remote code execution via the user-writable conf... 🔗 https://exploitgrid.net/cve/CVE-2026-77602

🛡️ #ExploitGrid Daily #Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-59167 CVE-2026-86708 CVE-2026-96257 CVE-2026-19599 CVE-2026-77602 ..🧵👇

🟠 HIGH PRIORITY ├ CVE-2026-59167 — SunEditor · XSS sanitizer bypass ├ CVE-2026-86708 — Sensitive data exposure ├ CVE-2026-96257 — Fast FAC1203R · Stack overflow ├ CVE-2026-19599 — Remote Code Execution └ CVE-2026-77602 — OpenC3 COSMOS · Auth'd RCE via writable config