OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-105105

CRITICAL · CVSS 9.8 EPSS 0.78% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-03 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The ait.core.server telemetry and command broker in NASA-AMMOS AIT-Core versions up to 3.1.1 is vulnerable due to missing authentication, allowing unauthenticated remote attackers to access the ZeroMQ message bus. This critical flaw enables attackers to inject malicious commands, exfiltrate sensitive telemetry data, and disrupt communication between spacecraft and ground systems. Organizations utilizing affected versions should prioritize immediate remediation, especially those operating in aerospace or critical infrastructure sectors.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-105105
Severity
CRITICAL
CVSS
9.8
EPSS
0.78%

Original NVD Description

CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS AIT-Core through 3.1.1 allows an unauthenticated remote attacker with network access to the ZeroMQ message bus to inject spacecraft command data, exfiltrate command and telemetry traffic, inject forged telemetry, or disrupt the command and telemetry bus. The ait-server ZeroMQ broker binds its XSUB and XPUB sockets to all network interfaces by default without authentication or transport security. An attacker able to reach TCP port 5559 can publish messages onto internal topics, including the __commands__ command topic. With the shipped default configuration, command messages are forwarded through command_stream and emitted on the command-uplink UDP path. An attacker able to reach TCP port 5560 can subscribe to command and telemetry traffic on the ground bus. AIT-Core 3.1.2 changes the default ZeroMQ bind addresses to loopback.