CVE-2026-60112: Nasa Ait GUI

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue arbitrary spacecraft commands by calling Sessions.create() without any credential check. Attackers can exploit the unauthenticated session issuance in Sessions.create() and subsequently invoke handle_cmd() to forward arbitrary commands directly to the AIT command bus without any authentication gate between session creation and command dispatch.

Affected products

  • Nasa Ait GUI: before 2.5.1 (fixed in 2.5.1)

Published 2026-07-29. Last modified 2026-08-18.