NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands
A security vulnerability in NASA/JPL's AMMOS Instrument Toolkit's AIT-GUI browser-based operator console allows unauthenticated attackers to issue arbitrary commands to spacecraft and instruments. Researchers at Cycode discovered a chain of flaws, initially identified by Saidakbarxon Maxsudxonov (CVE-2026-60112) and later confirmed by Cycode, that bypass authentication and authorization mechanisms. The vulnerability stems from a hardcoded IP address, unvalidated file paths, and a missing session check, leading to potential command execution and data compromise. While a fix was implemented in version 2.5.2, the initial vulnerability persisted in earlier versions and remains unpatched in the package ecosystem.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
