Critical Vulnerability in NASA Ground Control Software Allows Unauthenticated Access

Critical Vulnerability in NASA Ground Control Software Allows Unauthenticated Access

First seen 20 Aug 2026, 21:12 UTC Infosecurity-MagazineCybersecuritynewsBugcrowdFeeds.FeedburnerSecurityaffairs.Co+4 78.0

Article Content

Browse articles
ThreatCluster

A critical vulnerability in NASA's AMMOS Instrument Toolkit (AIT-GUI) software, tracked as GHSA-p9r8-2q67-fp86, allows unauthenticated attackers to issue commands to spacecraft and execute scripts. The flaw affects AIT-GUI versions up to 2.5.1 and has a CVSS rating of 9.4. Discovered by Cycode researcher Yuval Elbar on August 18, 2026, the vulnerability allows attackers to exploit access-control failures through an open web server interface. Attackers can gain access without being on the same network, potentially uploading malware via a malicious webpage. AIT-GUI 2.5.2 has been released to address this issue. The vulnerability also enables remote code execution through a chained exploit involving the /tlm/query endpoint. Administrators are advised to upgrade to the latest version and review security practices.

Key Points: • NASA's AIT-GUI software has a critical vulnerability allowing unauthenticated access. • The flaw affects versions up to 2.5.1 and has a CVSS score of 9.4. • Attackers can exploit the vulnerability remotely via a malicious webpage.

Timeline

2026-08-13
Vulnerability disclosed by Cycode researcher
Yuval Elbar reported a critical flaw in AIT-GUI that allows unauthenticated command execution.
Cybersecuritynews
2026-08-18
Vulnerability details published
Infosecurity Magazine reported on the critical vulnerability allowing command execution and script running.
Infosecurity-Magazine
2026-08-18
Patch released for AIT-GUI
NASA released AIT-GUI version 2.5.2 to fix the critical vulnerability identified by Cycode.
Infosecurity-Magazine
2026-08-21
Further coverage of vulnerability
Tech Radar and other outlets reported on the implications of the AIT-GUI vulnerability and recommended immediate upgrades.
Feeds.Feedburner