OS Command Injection in NASA HyperCP Software
CVE-2026-72579

7.5HIGH

Key Information:

Vendor

Nasa

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-72579?

An OS command injection flaw in NASA's HyperCP software exposes systems to potential unauthorized command execution. This vulnerability occurs when an attacker with network access can intercept or spoof responses from oceandata.sci.gsfc.nasa.gov, allowing them to manipulate the command execution process on a researcher's workstation. Proper security measures are crucial to safeguard against this type of exploit, which could result in the execution of arbitrary commands.

Affected Version(s)

HyperCP 0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adrian Gaitan
.