CVE-2026-67970

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive components via a path traversal.

Published 2026-08-03. Last modified 2026-08-31.