NASA ground software flaw exposes spacecraft commands
A critical authentication flaw in NASA’s open-source ground-control software could allow network attackers to obtain a valid session and transmit arbitrary spacecraft or instrument commands without supplying credentials. The vulnerability affects versions of the AMMOS Instrument Toolkit GUI released before version 2.5.1 and has been assigned CVE-2026-60112. The weakness carries a CVSS 4.0…
A critical authentication flaw in NASA's open-source ground-control software, AMMOS Instrument Toolkit GUI, could enable network attackers to transmit arbitrary spacecraft or instrument commands without providing credentials. Versions of the software released before 2.5.1 are affected, and the vulnerability has been assigned CVE-2026-60112.
The issue, classified as CWE-306, or Missing Authentication for Critical Function, carries a high CVSS vulnerability score of 9.8. Exploitation requires no prior privileges, user interaction, or unusual system conditions. The flaw stems from missing authentication around session creation, allowing attackers to invoke the software's session-creation function without a credential check and forward commands to the AIT command bus.
NASA's AMMOS Instrument Toolkit is a Python-based suite used for instrument uplink, downlink, and sequencing. No publicly documented exploitation has been identified, and no NASA mission has been compromised through the flaw. Operators using versions of AIT-GUI older than 2.5.1 should update the software and review network connectivity to minimize exposure.
Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.