top of page
perceptive_background_267k.jpg

AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a val…

Published:

29 July 2026 at 00:00:00

Alert date:

29 July 2026 at 19:02:28

Source:

nvd.nist.gov

Click to open the original link from this advisory

Critical Infrastructure, Identity & Access, Web Technologies

AMMOS Instrument Toolkit (AIT) GUI versions before 2.5.1 contain a critical missing authentication vulnerability tracked as CVE-2026-60112. An unauthenticated network attacker can call Sessions.create() without any credential check to obtain a valid session. Once a session is established, the attacker can invoke handle_cmd() to forward arbitrary commands directly to the AIT command bus. There is no authentication gate between session creation and command dispatch, making the attack chain straightforward. This vulnerability affects spacecraft ground systems, posing a significant risk to space mission operations. The issue has been patched in AIT GUI version 2.5.1. References include the official GitHub changelog, the specific fix commit, the release tag, and a VulnCheck advisory. Organizations using AIT GUI should upgrade to version 2.5.1 immediately to mitigate this critical risk.

Technical details

Mitigation steps:

Affected products:

AMMOS Instrument Toolkit (AIT) GUI

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page