CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-60112 — AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authenticatio...

·Source: NIST NVD

Updated:

Executive Summary

AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue arbitrary spacecraft commands by calling Sessions.create() without any credential check. Attackers can exploit the unauthenticated session issuance in Sessions.create() and subsequently invoke handle_cmd() to forward ar

Analysis

AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue arbitrary spacecraft commands by calling Sessions.create() without any credential check. Attackers can exploit the unauthenticated session issuance in Sessions.create() and subsequently invoke handle_cmd() to forward arbitrary commands directly to the AIT command bus without any authentication gate between session creation and command dispatch. CVSS Score: 9.8. Published: 2026-07-29T16:17:55.413.

Indicators of Compromise (1)

CVE (1)
CVE-2026-60112
Source Attribution

Originally published by NIST NVD on Jul 29, 2026. Verified by: NIST.

Related Threats