CVE-2026-60113
NASA-AMMOS · AIT-DSN
A missing authentication vulnerability in the NASA-AMMOS AIT-DSN Space Link Extension interface allows unauthenticated remote attackers to execute arbitrary API commands.
Executive summary
The NASA-AMMOS AIT-DSN toolkit contains a critical authentication bypass vulnerability that allows unauthenticated network attackers to control spacecraft communication sessions.
Vulnerability
This vulnerability involves a lack of authentication checks within the Space Link Extension interface manager. An unauthenticated attacker can send direct HTTP requests to seven unprotected API routes, granting them the ability to manipulate DSN sessions and inject telemetry data.
Business impact
Successful exploitation poses a severe risk to mission integrity and operational control. By manipulating Deep Space Network communication sessions or injecting arbitrary frames, an attacker could disrupt critical telemetry data or potentially influence spacecraft operations. Given the CVSS score of 9.8, this vulnerability represents a critical threat that could lead to complete loss of command authority over affected communication links.
Remediation
Immediate Action: Upgrade to NASA-AMMOS AIT-DSN version 2.2.2 or later immediately to implement mandatory authentication for all API endpoints.
Proactive Monitoring: Review access logs for unusual HTTP traffic directed toward the Space Link Extension API routes, specifically looking for unauthorized session creation or termination requests.
Compensating Controls: Deploy a Web Application Firewall or network access control list to restrict access to the AIT-DSN interface to known, authorized IP addresses only.
Exploitation status
Public Exploit Available: No (unknown)
Analyst recommendation
This vulnerability presents a high-risk scenario for any organization utilizing the AIT-DSN toolkit. Administrators must prioritize updating to version 2.2.2 to ensure that critical API routes are properly protected against unauthorized access. Failure to patch allows any network-adjacent actor to interfere with sensitive spacecraft communication protocols.