Missing Authentication Vulnerability in AMMOS Instrument Toolkit DSN Interface by NASA
CVE-2026-60113
9.3CRITICAL
What is CVE-2026-60113?
The AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface prior to version 2.2.2 is susceptible to a significant security flaw due to missing authentication in its Space Link Extension (SLE) interface manager. This vulnerability allows unauthenticated attackers to access seven unprotected API routes through direct HTTP requests. Exploiting this flaw could permit attackers to initiate or terminate Deep Space Network communication sessions, extract telemetry frame data, and even inject arbitrary frames into active spacecraft links, endangering the integrity and security of space operations.
Affected Version(s)
AIT-DSN 0
