Space Security News
  • Home
  • News

    Unnamed defense customers reserve payload room on Dream Chaser’s first flight

    September 5, 2026

    Chinese satellite in a rare retrograde orbit leaves 43 tracked fragments

    September 5, 2026

    France’s space summit loses its US heavyweights over White House warnings

    September 5, 2026

    The Space Force changes commanders as Schiess pledges deliberate growth

    September 5, 2026
  • Features

    Darknavy claims full control of the newest Starlink terminals

    September 3, 2026

    Allied radar net watching geostationary orbit gains Wales outpost

    September 3, 2026

    Royal Air Force promotes space to a top-tier command role

    September 3, 2026

    Pentagon pays space suppliers to scale output ahead of a fleet boom

    September 3, 2026
  • Spotlight
  • Events
  • About Us
    • Mission
    • Services
    • Contact Us
Reading: Flaws in NASA command console let anyone fire spacecraft commands
Share
Search
  • Trending:
  • Alliances
  • Cislunar
  • Commercial
  • Communications
  • Cyber
  • Debris
  • Defense
  • Deterrence
  • Intelligence
  • Launch
  • Strategy
  • Surveillance
  • Missile
  • Navigation
  • War
Font ResizerAa
Space Security NewsSpace Security News
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About Us
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About Us
    • Mission
    • Services
    • Contact Us
Follow US
© 2026 Space Security News. All Rights Reserved.
News

Flaws in NASA command console let anyone fire spacecraft commands

Critical flaws in NASA/JPL's AIT-GUI console allowed unauthenticated users to send commands to spacecraft.

By
SSN Staff
Last updated: August 24, 2026
2 Min Read
Share

NASA/JPL’s open-source spacecraft command console lacked working authentication on its state-changing endpoints, letting anyone who reached the port issue commands, researchers found.

Cycode’s researchers dug into AIT-GUI, the browser-based operator console of NASA/JPL’s open-source AMMOS Instrument Toolkit, and found its web server bound to every network interface on port 8080, ignoring the configured host setting.

No login, session gate or CSRF protection guarded routes including POST /cmd, which passes input straight to the command bus. A session cookie is handed out to any request for the root page, so an attacker can obtain one without credentials and send commands on a second request. Two other endpoints built filesystem paths from raw input, enabling traversal outside script and sequence directories.

The advisory GHSA-p9r8-2q67-fp86 rates the chain critical at CVSS 9.4. No CVE has been assigned. Because the routes accept form-encoded bodies that browsers treat as simple requests, a webpage an operator merely visits can deliver a cross-origin POST without preflight, the researchers said.

Cycode framed the impact bluntly: an unauthenticated command results in issued instrument commands, not a defaced page. Researcher Yuval Elbar called the console a web GUI that listens on every interface, asks nobody for a password and can be steered by any page an operator opens.

The flaws were fixed in AIT-GUI 2.5.2, released in mid-August, which binds the configured host, rejects cross-origin state changes and confines script and sequence endpoints to their roots. Cycode urged operators to upgrade and keep the port off untrusted networks.

TAGGED:AMMOSCycodeground segmentNASAsatellite securityspacecraft commandvulnerability
SOURCES:Security AffairsThe Hacker News

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print

LATEST NEWS

Unnamed defense customers reserve payload room on Dream Chaser’s first flight

News
September 5, 2026

Chinese satellite in a rare retrograde orbit leaves 43 tracked fragments

US tracking counts 43 fragments after a Chinese satellite in a rare retrograde orbit breaks…

September 5, 2026

France’s space summit loses its US heavyweights over White House warnings

SpaceX and Blue Origin lead US withdrawals from Macron's summit after Washington advises firms to…

September 5, 2026

The Space Force changes commanders as Schiess pledges deliberate growth

Gen. Douglas Schiess succeeds Chance Saltzman as chief of space operations with growth and deterrence…

September 5, 2026

YOU MAY ALSO LIKE

Sphinx Defense to build software heart of new nuclear command satellite network

Space Systems Command picks Sphinx Defense to build the ground software hub for the military’s next-generation nuclear command and control…

News
July 30, 2026

Unseen drone threats endanger US rocket launch sites, experts warn

Drone incursions at Vandenberg and Cape Canaveral expose vulnerabilities in US space launch infrastructure as launch tempo accelerates toward 300…

NewsSatellite SecurityThreat Actors & Incidents
July 18, 2026

European firms plan exo-atmospheric interceptor for 2027 test

Destinus-led consortium of five European defense firms plans to develop and test a sovereign exo-atmospheric interceptor by 2027.

NewsSatellite SecurityThreat Actors & Incidents
July 18, 2026

Space acquisition chief fears reform could stall satellite programs

Space Systems Command's chief says the acquisition overhaul must not distract from delivering satellite programs on time.

News
August 9, 2026

Breaking developments in space and cybersecurity, decoded for the modern defense and technology landscape.

Follow us: 

  • News
  • Features
  • Spotlight
  • Events
  • About Us
  • Mission
  • Services
  • Contact Us
Copyright © 2026 Space Security News. All Rights Reserved.
Privacy Policy | Legal
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?