Vulnary
← back to the feed
Critical· 9.3official fix available

CVE-2026-60112

The AIT GUI before version 2.5.1 allows anyone on the network to create a session without authentication and then send arbitrary spacecraft commands. This flaw lets an attacker gain full control over the spacecraft’s command bus.

publishedJul 29, 2026
last modifiedJul 29, 2026
sourcesNVD
severity · cvss
9.3
critical · how bad it is
exploitation · epss
n/a
chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Aug 28, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

AMMOS Instrument Toolkit (AIT) GUI, all versions earlier than 2.5.1.

02

Real-world impact

An attacker could issue any command to the spacecraft, potentially hijacking its operations, causing mission failure, or compromising safety.

03

Why this severity

The CVSS score of 9.3 reflects the vulnerability’s high confidentiality, integrity, and availability impact combined with its low attack complexity and lack of user interaction. An unauthenticated attacker can fully control the spacecraft, making the risk critical.

04

What to do about it

official fix available
recommended steps
  1. 01Upgrade the AIT GUI to version 2.5.1 or later.
  2. 02Restart the AIT service to apply the update.

NVD description

05

Timeline

  1. Jul 29, 2026 · 20h ago
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 29, 2026 · 19h ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Attack requirementsNone
Privileges requiredNone
User interactionNone needed
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →