← Back to Daily Briefing (#MITRE)

A critical authentication bypass vulnerability (GHSA-p9r8-2q67-fp86) has been identified in the NASA/JPL AMMOS Instrument Toolkit GUI (AIT-GUI), a browser-based console used for spacecraft operations. The flaw stems from a failure to enforce authentication on the software's command bus, allowing unauthenticated remote attackers to bypass login requirements entirely. This vulnerability enables the issuance of arbitrary commands, execution of command sequences, and the running of arbitrary scripts directly against spacecraft and scientific instruments. With a CVSS v3.1 score of 9.4, this flaw represents an existential threat to mission integrity and the operational control of space assets.

  • Vulnerability Overview: Technical Scope

    • Affected Component: AMMOS Instrument Toolkit GUI (AIT-GUI).
    • Vulnerability Identifier: GHSA-p9r8-2q67-fp86.
    • Severity Rating: Critical (CVSS v3.1 score of 9.4).
    • Primary Flaw: Complete lack of authentication enforcement for the internal command bus.
  • Attack Mechanics: Deep Dive

    • Attack Vector: Remote exploitation via the browser-based operator console.
    • Bypass Method: Direct interaction with the command bus, bypassing the application's login layer.
    • Exploitation Capabilities: Execution of arbitrary scripts and complex command sequences.
    • Access Requirement: Zero (Unauthenticated remote access).
  • Operational Impact: Mission Risk

    • Spacecraft Control: High potential for unauthorized spacecraft takeover and total loss of mission control.
    • Instrument Manipulation: Ability to maliciously alter or disable critical scientific instrumentation.
    • Mission Integrity: Direct path for adversaries to disrupt active space missions via arbitrary command injection.
  • Research and Disclosure

    • Discovery: Identified and disclosed by lead security researcher Yuval Elbar and the Cycode team.
    • Timeline: Flaw disclosed in mid-August 2026.
    • Documentation: Tracked via the GitHub Security Advisory system to ensure coordinated remediation.
  • Remediation and Defense

    • Primary Fix: Update AIT-GUI to the latest version to ensure the command bus enforces strict authentication.
    • Network Controls: Implement strict network segmentation and air-gapping for spacecraft control consoles.
    • Monitoring: Enable detailed logging and alerting for any unauthenticated requests hitting the command bus interface.

Related posts

  1. simplysecuregroup.com — Critical NASA AIT-GUI Flaw Lets Unauthenticated Attackers Issue Spacecraft Commands
  2. Cybersecurity News — Critical NASA AIT-GUI Flaw Lets Unauthenticated Attackers Issue Spacecraft Commands
  3. feeds.feedburner.com — NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands
  4. Infosecurity-magazine
  5. Facebook
  6. Itbrief
  7. Ground
  8. Teamwin
  9. Cycode
  10. Scworld

LINK COPIED TO CLIPBOARD