An issue in Yamcs 5.8.6 allows attackers to obtain the session cookie via upload of crafted HTML file.