


Perceptive Security
SOC/SIEM Consultancy

The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service's REST API …
Published:
4 augustus 2026 om 22:00:00
Alert date:
5 augustus 2026 om 14:10:56
Source:
nvd.nist.gov
Critical Infrastructure, Network Infrastructure, Identity & Access, Cloud & Virtualization
CVE-2026-71289 affects the NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation, where the default docker-compose.yml exposes the amp-manager REST API directly on the host network (port 8089), bypassing the CAM authentication gateway. The CivetWeb-based REST server in JHUAPL/dtnma-tools is configured with auth domain checks disabled and uses null authentication callbacks for all routes. This allows any network-reachable client to enumerate registered DTNMA agents, dispatch arbitrary EXECSET-encoded command sets to them, and clear stored reports without any credentials. The vulnerability is compounded by elevated Docker capabilities (NET_ADMIN, NET_RAW, SYS_NICE) granted to the container. Both NASA-AMMOS/anms and JHUAPL-DTNMA/dtnma-tools repositories are affected as published. The impacted components manage DTNMA agents that may represent simulated or real spacecraft and ground nodes depending on deployment context, raising significant operational risk in non-isolated environments.
Technical details
Mitigation steps:
Affected products:
NASA-AMMOS ANMS
JHUAPL-DTNMA dtnma-tools
CivetWeb REST server
Docker amp-manager service
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-71289
https://github.com/JHUAPL-DTNMA/dtnma-tools
https://github.com/NASA-AMMOS/anms
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
