CVE-2026-42084 Details
Description
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3.
A vulnerability in OpenC3 COSMOS versions prior to 6.10.5 and 7.0.0-rc3 allows users to change their passwords without providing the old password, instead using a valid session token. This flaw can be exploited by an attacker who has obtained a valid session token to hijack an account, including admin accounts, and prevent legitimate users from accessing it. The issue arises from a design flaw in the authentication model, where session tokens and passwords are interchangeable for authentication purposes. After a password change, the old token remains valid, allowing continued access to the compromised account.
Users should upgrade to OpenC3 COSMOS versions 6.10.5 or 7.0.0-rc3.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/OpenC3/cosmos/security/advisories/GHSA-wgx6-g857-jjf7 | CISA-ADP | ExploitVendor Advisory |
| https://github.com/OpenC3/cosmos/commit/2e623714e3426d5ae81b6f8239d4a2a6937ef776 | [email protected] | Patch |
| https://github.com/OpenC3/cosmos/releases/tag/v6.10.5 | [email protected] | Release Notes |
| https://github.com/OpenC3/cosmos/releases/tag/v7.0.0-rc3 | [email protected] | Release Notes |
| https://github.com/OpenC3/cosmos/security/advisories/GHSA-wgx6-g857-jjf7 | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-620 | Unverified Password Change | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openc3 cosmos | < 6.10.5 7.0.0 rc1 7.0.0 rc2 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 8, 2026 | Initial Analysis | [email protected] |
| May 6, 2026 | CVE Modified | CISA-ADP |
| May 4, 2026 | New CVE Received | [email protected] |