logo

NASA AIT-GUI Critical Vulnerability: Unauthenticated Spacecraft Commands

ID: 209bcb57-6489-5c01-9024-d9ef1b016568

STIX ID: report--209bcb57-6489-5c01-9024-d9ef1b016568

Feed Name: CyberNexora News

Threat Score
90/100

Date Published: 2026-08-20

Date Updated: 2026-08-20

Author: Debolina Barik

...
...

**Executive summary:** The report details a critical vulnerability in NASA/JPL's AIT-GUI (CVE-2026-60112) that can allow unauthenticated remote actors to invoke command and script execution, potentially affecting spacecraft and scientific instruments; the issue involves missing authentication/authorization, lack of CSRF protection, path traversal risks, and possible exposure when bound to 0.0.0.0:8080, and was addressed in AIT-GUI version 2.5.2 with recommended mitigation steps including patching, access restrictions, and log review.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.