


Perceptive Security
SOC/SIEM Consultancy

AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a val…
Published:
29 juli 2026 om 00:00:00
Alert date:
29 juli 2026 om 19:02:28
Source:
nvd.nist.gov
Critical Infrastructure, Identity & Access, Web Technologies
AMMOS Instrument Toolkit (AIT) GUI versions before 2.5.1 contain a critical missing authentication vulnerability tracked as CVE-2026-60112. An unauthenticated network attacker can call Sessions.create() without any credential check to obtain a valid session. Once a session is established, the attacker can invoke handle_cmd() to forward arbitrary commands directly to the AIT command bus. There is no authentication gate between session creation and command dispatch, making the attack chain straightforward. This vulnerability affects spacecraft ground systems, posing a significant risk to space mission operations. The issue has been patched in AIT GUI version 2.5.1. References include the official GitHub changelog, the specific fix commit, the release tag, and a VulnCheck advisory. Organizations using AIT GUI should upgrade to version 2.5.1 immediately to mitigate this critical risk.
Technical details
Mitigation steps:
Affected products:
AMMOS Instrument Toolkit (AIT) GUI
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-60112
https://github.com/NASA-AMMOS/AIT-GUI/blob/2.5.1/CHANGELOG.md
https://github.com/NASA-AMMOS/AIT-GUI/commit/beb8fc0813eded89f985d3eb9a73535dd327726d
https://github.com/NASA-AMMOS/AIT-GUI/releases/tag/2.5.1
https://www.vulncheck.com/advisories/ait-gui-missing-authentication-via-sessions-create
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
