SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-60113

CRITICAL · CVSS 9.8 EPSS 0.53% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

The AMMOS Instrument Toolkit's Deep Space Network Interface prior to version 2.2.2 is critically vulnerable due to a missing authentication flaw in its Space Link Extension interface, allowing unauthenticated attackers to access seven unsecured API routes. This vulnerability enables malicious actors to manipulate Deep Space Network communication sessions, retrieve sensitive telemetry data, and inject arbitrary frames into spacecraft links, posing significant risks to mission integrity and security. Organizations utilizing this toolkit, particularly those involved in space operations and telemetry management, should prioritize immediate remediation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-60113
Severity
CRITICAL
CVSS
9.8
EPSS
0.53%

Original NVD Description

AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager that allows unauthenticated network attackers to access seven unprotected API routes by sending direct HTTP requests with no credentials. Attackers can reach the exposed SLE endpoints to start or stop Deep Space Network communication sessions, retrieve telemetry frame data, and inject arbitrary frames into active spacecraft links.

Related CVEs

Other vulnerabilities affecting the same vendor(s)