Skip to content
COOEY

EXPOSURES › CVE-2026-60112

CVE-2026-60112

CRITICAL
DETAIL
SourceNVD · cve Published2026-07-29 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-60112 ↗

▸ RECOMMENDED ACTION  Critical severity — schedule patching of the affected products.

DESCRIPTION

AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue arbitrary spacecraft commands by calling Sessions.create() without any credential check. Attackers can exploit the unauthenticated session issuance in Sessions.create() and subsequently invoke handle_cmd() to forward arbitrary commands directly to the AIT command bus without any authentication gate between session creation and command dispatch.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.