EXPOSURES › CVE-2026-60112
CVE-2026-60112
CRITICAL
DETAIL
SourceNVD · cve
Published2026-07-29
CVSS9.8
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-60112 ↗
▸ RECOMMENDED ACTION Critical severity — schedule patching of the affected products.
DESCRIPTION
AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue arbitrary spacecraft commands by calling Sessions.create() without any credential check. Attackers can exploit the unauthenticated session issuance in Sessions.create() and subsequently invoke handle_cmd() to forward arbitrary commands directly to the AIT command bus without any authentication gate between session creation and command dispatch.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.