CRITICAL🇵🇱 Wersja polska

CVE-2026-42087

CVSS 9.6v3.1pub. 2026-05-04upd. 2026-05-08

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.0 to before version 7.0.0-rc3, a SQL injection vulnerability exists in the Time-Series Database (TSDB) component of COSMOS. The tsdb_lookup function in the cvt_model.rb file directly places user-supplied input into a SQL query without sanitizing the input. As a result, a user can break out of the initial SQL statement and execute arbitrary SQL commands, including deleting data. This issue has been patched in version 7.0.0-rc3.

🤖 AI Analysis
How it works

The tsdb_lookup function in the cvt_model.rb file directly embeds user-supplied input into the SQL query without prior sanitization. An attacker can interrupt the original SQL query and inject arbitrary SQL commands. The vulnerability is remotely accessible to an authenticated user without requiring victim interaction, and exploitation does not require high privileges (PR:L).

Impact

An attacker can read, modify, and delete data stored in the COSMOS system database, and potentially affect data from monitored embedded systems. High impact on data confidentiality and integrity (C:H, I:H) with no impact on availability (A:N).

Mitigation & patch

Update OpenC3 COSMOS to version 7.0.0-rc3 or later, where the vulnerability has been removed. Details available in vendor references: https://github.com/OpenC3/cosmos/releases/tag/v7.0.0-rc3

Who is affected

OpenC3 COSMOS versions from 6.7.0 to (not including) 7.0.0-rc3

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
  • Openc3 Cosmos

    APP
    Openc3
    7.0.06.7.0 – 7.0.0 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2026-42088CRITICAL9.6PL ✓same product

OpenC3 COSMOS: ominięcie uprawnień API i dostęp do usług wewnętrznych sieci Docker

CVE-2025-28384CRITICAL9.1PL ✓same product

Path Traversal w endpoincie /script-api/scripts/ OpenC3 COSMOS

CVE-2025-28386CRITICAL9.8PL ✓same product

RCE w komponencie Plugin Management OpenC3 COSMOS poprzez spreparowany plik .txt

CVE-2025-28388CRITICAL9.8PL ✓same product

OpenC3 COSMOS — hardcoded credentials w koncie Service Account

CVE-2025-28389CRITICAL9.8PL ✓same product

OpenC3 COSMOS: Obejście uwierzytelnienia przez słabe wymagania haseł