Network Management System Vulnerability in NASA-AMMOS and JHUAPL-DTNMA Tools
CVE-2026-71289

9.8CRITICAL

Key Information:

Vendor

Nasa-ammos

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-71289?

A configuration issue in the NASA-AMMOS Asynchronous Network Management System and JHUAPL-DTNMA tools allows the amp-manager service's REST API to be exposed directly to the host network. Due to misconfigurations in the default docker-compose.yml file, critical security boundaries are bypassed, permitting unauthorized clients to access a variety of sensitive operations without authentication. This includes enumerating registered agents and submitting arbitrary command sets, all without requiring credentials. The affected services accept commands that could manipulate registered agents, endangering the integrity of the entire management network. Proper security measures and configurations must be implemented to safeguard against unauthorized access.

Affected Version(s)

anms 0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Saidakbarxon Maxsudxonov
.