Network Management System Vulnerability in NASA-AMMOS and JHUAPL-DTNMA Tools
CVE-2026-71289
What is CVE-2026-71289?
A configuration issue in the NASA-AMMOS Asynchronous Network Management System and JHUAPL-DTNMA tools allows the amp-manager service's REST API to be exposed directly to the host network. Due to misconfigurations in the default docker-compose.yml file, critical security boundaries are bypassed, permitting unauthorized clients to access a variety of sensitive operations without authentication. This includes enumerating registered agents and submitting arbitrary command sets, all without requiring credentials. The affected services accept commands that could manipulate registered agents, endangering the integrity of the entire management network. Proper security measures and configurations must be implemented to safeguard against unauthorized access.
Affected Version(s)
anms 0
