Government security

NASA ground control software vulnerability could allow spacecraft access

NASA's ground control software has a critical vulnerability that could allow third-party access to spacecraft, with further coverage provided by Tech Radar.

A browser-based variant of NASA's AMMOS Instrument Toolkit (AIT), specifically versions up to 2.5.1, has a critical vulnerability that could allow an unauthenticated attacker to issue commands to spacecraft and instruments, and potentially execute server-side scripts, as discovered by Cycode researchers. The flaw, disclosed on August 18, 2026, stems from the AIT-GUI running as a web server with an open network interface and lacking authentication, authorization, or cross-site request forgery (CSRF) protection. This allows attackers to exploit basic access-control failings, potentially enabling them to upload files, including malware, directly to NASA craft via a vulnerable browser session.

The attacker does not need to be on the same network, as access can be gained through an exposed port or by tricking an operator into visiting a malicious webpage. Cycode advises administrators to upgrade AIT-GUI to version 2.5.2, check console ports, and review command history.

Source: Tech Radar

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds