{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-60112/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-60112"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AMMOS Instrument Toolkit (AIT) GUI (\u003c 2.5.1)"],"_cs_severities":["critical"],"_cs_tags":["authentication-bypass","cve-2026-60112","critical-infrastructure"],"_cs_type":"advisory","_cs_vendors":["NASA"],"content_html":"\u003cp\u003eThe AMMOS Instrument Toolkit (AIT) GUI, used for spacecraft command and control, contains a critical authentication vulnerability (CVE-2026-60112) affecting versions prior to 2.5.1. The flaw exists within the Sessions.create() method, which fails to enforce credential validation during session initiation. An unauthenticated network attacker can leverage this failure to establish a valid user session. Once authenticated, the attacker can interact with the handle_cmd() function, which lacks internal security checks, allowing the injection of arbitrary commands directly into the AIT command bus. This vulnerability poses a severe risk to mission-critical infrastructure, as it grants unauthorized remote control over spacecraft operations without requiring valid user authentication or authorization tokens.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs network reconnaissance to identify reachable instances of the AIT GUI.\u003c/li\u003e\n\u003cli\u003eAttacker initiates an unauthenticated connection request to the AIT web interface.\u003c/li\u003e\n\u003cli\u003eAttacker triggers the vulnerable Sessions.create() method without providing valid credentials.\u003c/li\u003e\n\u003cli\u003eThe application generates and returns a valid session token due to missing validation logic.\u003c/li\u003e\n\u003cli\u003eAttacker utilizes the assigned session token to access privileged application endpoints.\u003c/li\u003e\n\u003cli\u003eAttacker calls the handle_cmd() function with malicious command parameters.\u003c/li\u003e\n\u003cli\u003eThe application forwards the injected commands directly to the command bus.\u003c/li\u003e\n\u003cli\u003eUnauthorized commands are executed by the target system or downstream spacecraft hardware.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to gain full command-line control over the AIT command bus. This permits unauthorized execution of arbitrary spacecraft commands, potentially leading to mission degradation, loss of control over satellite instruments, or permanent hardware damage. Any organization utilizing versions of AIT GUI earlier than 2.5.1 in network-exposed environments is at immediate risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade to AIT GUI version 2.5.1 or later immediately to patch the missing authentication logic in Sessions.create().\u003c/li\u003e\n\u003cli\u003eRestrict network access to the AIT GUI interface to trusted management networks only, preventing exposure to untrusted segments.\u003c/li\u003e\n\u003cli\u003eAudit web server and application logs for anomalous POST requests to the session creation endpoints that do not correspond to known valid login attempts.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-07-29T16:20:52Z","date_published":"2026-07-29T16:20:52Z","id":"https://feed.craftedsignal.io/briefs/2026-07-ait-auth-bypass/","summary":"The AMMOS Instrument Toolkit (AIT) GUI before version 2.5.1 allows unauthenticated attackers to bypass credential checks to establish sessions and issue arbitrary spacecraft commands.","title":"Authentication Bypass in AMMOS Instrument Toolkit GUI","url":"https://feed.craftedsignal.io/briefs/2026-07-ait-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-60112","version":"https://jsonfeed.org/version/1.1"}