Missing Authentication Vulnerability in AMMOS Instrument Toolkit GUI by NASA
CVE-2026-60112
9.3CRITICAL
What is CVE-2026-60112?
The AMMOS Instrument Toolkit (AIT) GUI prior to version 2.5.1 suffers from a missing authentication vulnerability that allows unauthorized network attackers to create valid sessions. This flaw occurs when calling the Sessions.create() method, which lacks a credential verification process. As a result, attackers can exploit this vulnerability to send arbitrary commands directly to the AIT command bus by invoking handle_cmd() without any authentication checks between session creation and command execution, posing significant risks to spacecraft operations.
Affected Version(s)
AIT-GUI 0
