Missing Authentication Vulnerability in AMMOS Instrument Toolkit DSN Interface by NASA
CVE-2026-60113

9.3CRITICAL

Key Information:

Vendor

Nasa-ammos

Status
Vendor
CVE Published:
29 July 2026

What is CVE-2026-60113?

The AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface prior to version 2.2.2 is susceptible to a significant security flaw due to missing authentication in its Space Link Extension (SLE) interface manager. This vulnerability allows unauthenticated attackers to access seven unprotected API routes through direct HTTP requests. Exploiting this flaw could permit attackers to initiate or terminate Deep Space Network communication sessions, extract telemetry frame data, and even inject arbitrary frames into active spacecraft links, endangering the integrity and security of space operations.

Affected Version(s)

AIT-DSN 0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Saidakbarxon Maxsudxonov
VulnCheck
.