CRITICALVulnerability
Verified
Global
NVD CRITICAL: CVE-2026-60112 — AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authenticatio...
·Source: NIST NVD
Updated:
Executive Summary
AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue arbitrary spacecraft commands by calling Sessions.create() without any credential check. Attackers can exploit the unauthenticated session issuance in Sessions.create() and subsequently invoke handle_cmd() to forward ar
Analysis
AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue arbitrary spacecraft commands by calling Sessions.create() without any credential check. Attackers can exploit the unauthenticated session issuance in Sessions.create() and subsequently invoke handle_cmd() to forward arbitrary commands directly to the AIT command bus without any authentication gate between session creation and command dispatch. CVSS Score: 9.8. Published: 2026-07-29T16:17:55.413.