CVE-2026-77602

LOWCVSS 9.9 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.1.0 until 7.3.0, authenticated non-administrator users can write content under targets_modified/ that is later executed by multiple configuration paths below the intended code-execution privilege tier. Table and command or telemetry definitions are processed through ConfigParser, PacketConfig, GENERIC_READ_CONVERSION, or GENERIC_WRITE_CONVERSION, allowing ERB rendering or Ruby and Python evaluation, while openc3-cosmos-script-runner-api/scripts/run_suite_analysis.rb executes suite procedure files through require. Storage uploads, screen saves, and script creation can place content in the overlay, and triggering table processing, a cmd/tlm reload, or suite analysis executes the content in cmd-tlm-api, decom microservices, or Script Runner with access to internal credentials and data. This issue is fixed in version 7.3.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-09-24: 309-24
Referenced assets1 URL
By indicator
Full discourse3 posts
  • ExploitGrid@exploitgrid

    [CVE] CVE-2026-77602 [HIGH PRIORITY] #OpenC3 COSMOS: Authenticated remote code execution via the user-writable conf... 🔗 https://exploitgrid.net/cve/CVE-2026-77602

    1000026
    47 followersView on X
  • ExploitGrid@exploitgrid

    🛡️ #ExploitGrid Daily #Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-59167 CVE-2026-86708 CVE-2026-96257 CVE-2026-19599 CVE-2026-77602 ..🧵👇

    1000044
    47 followersView on X
  • ExploitGrid@exploitgrid

    🟠 HIGH PRIORITY ├ CVE-2026-59167 — SunEditor · XSS sanitizer bypass ├ CVE-2026-86708 — Sensitive data exposure ├ CVE-2026-96257 — Fast FAC1203R · Stack overflow ├ CVE-2026-19599 — Remote Code Execution └ CVE-2026-77602 — OpenC3 COSMOS · Auth'd RCE via writable config

    1000038
    47 followersView on X

Explore more