Vulnary
← back to the feed
Critical· 9.1official fix available

CVE-2026-47731

The AMMOS Instrument Toolkit’s Binary Stream Capture component has a path‑traversal flaw that lets unauthenticated users write files anywhere on the host. By sending crafted HTTP requests, an attacker can cause the service to append data to arbitrary files, potentially exposing sensitive information or inserting malicious content. The flaw is critical because it can be triggered remotely over the network or via a malicious local website.

publishedJul 21, 2026
last modifiedJul 23, 2026
sourcesNVD
severity · cvss
9.1
critical · how bad it is
exploitation · epss
<1%
53th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Aug 21, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

AIT‑Core versions before 3.1.1 and 2.x before 2.6.1, specifically the Binary Stream Capture (BSC) component of the AMMOS Instrument Toolkit used in CubeSat and ground‑data‑system operations.

02

Real-world impact

A remote attacker can write arbitrary files with the privileges of the ait‑bsc process, enabling data exfiltration, tampering with logs, or inserting malicious code. The attack can be launched from the local network through a malicious website, even if the service is only reachable on localhost.

03

Why this severity

The CVSS score of 9.1 reflects a network attack vector, low complexity, no required privileges, no user interaction, and high impact on integrity and availability. The vulnerability allows remote modification of system files, which can compromise the system’s integrity and availability.

04

What to do about it

official fix available
recommended steps
  1. 01Upgrade the AMMOS Instrument Toolkit to version 3.1.1 or 2.6.1.
  2. 02Restart the ait‑bsc service after the upgrade.

NVD-referenced vendor advisory

05

Timeline

  1. Jul 21, 2026 · 11d ago
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 22, 2026 · 10d ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeUnchanged
Confidentiality impactNone
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →