CVE-2026-60112
The AIT GUI before version 2.5.1 allows anyone on the network to create a session without authentication and then send arbitrary spacecraft commands. This flaw lets an attacker gain full control over the spacecraft’s command bus.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
AMMOS Instrument Toolkit (AIT) GUI, all versions earlier than 2.5.1.
Real-world impact
An attacker could issue any command to the spacecraft, potentially hijacking its operations, causing mission failure, or compromising safety.
Why this severity
The CVSS score of 9.3 reflects the vulnerability’s high confidentiality, integrity, and availability impact combined with its low attack complexity and lack of user interaction. An unauthenticated attacker can fully control the spacecraft, making the risk critical.
What to do about it
- 01Upgrade the AIT GUI to version 2.5.1 or later.
- 02Restart the AIT service to apply the update.
NVD description
Timeline
- Jul 29, 2026 · 20h agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 29, 2026 · 19h agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.