SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-60112

CRITICAL · CVSS 9.8 EPSS 0.53% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

The AMMOS Instrument Toolkit (AIT) GUI prior to version 2.5.1 is vulnerable due to a missing authentication mechanism, enabling unauthenticated network attackers to create valid sessions and issue arbitrary commands to spacecraft systems. This critical vulnerability allows attackers to bypass authentication entirely, posing severe risks to the integrity and security of spacecraft operations. Organizations utilizing AIT should prioritize immediate updates to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-60112
Severity
CRITICAL
CVSS
9.8
EPSS
0.53%

Original NVD Description

AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue arbitrary spacecraft commands by calling Sessions.create() without any credential check. Attackers can exploit the unauthenticated session issuance in Sessions.create() and subsequently invoke handle_cmd() to forward arbitrary commands directly to the AIT command bus without any authentication gate between session creation and command dispatch.

Related CVEs

Other vulnerabilities affecting the same vendor(s)