CVE-2026-60112
EUVD-2026-5039629.07.2026, 16:17
AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue arbitrary spacecraft commands by calling Sessions.create() without any credential check. Attackers can exploit the unauthenticated session issuance in Sessions.create() and subsequently invoke handle_cmd() to forward arbitrary commands directly to the AIT command bus without any authentication gate between session creation and command dispatch.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| nasa | ait_gui | 𝑥 < 2.5.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration