Space Security News
  • Home
  • News

    Unnamed defense customers reserve payload room on Dream Chaser’s first flight

    September 5, 2026

    Chinese satellite in a rare retrograde orbit leaves 43 tracked fragments

    September 5, 2026

    France’s space summit loses its US heavyweights over White House warnings

    September 5, 2026

    The Space Force changes commanders as Schiess pledges deliberate growth

    September 5, 2026
  • Features

    Darknavy claims full control of the newest Starlink terminals

    September 3, 2026

    Allied radar net watching geostationary orbit gains Wales outpost

    September 3, 2026

    Royal Air Force promotes space to a top-tier command role

    September 3, 2026

    Pentagon pays space suppliers to scale output ahead of a fleet boom

    September 3, 2026
  • Spotlight
  • Events
  • About Us
    • Mission
    • Services
    • Contact Us
Reading: Flaws in NASA command console let anyone fire spacecraft commands
Share
Search
  • Trending:
  • Alliances
  • Cislunar
  • Commercial
  • Communications
  • Cyber
  • Debris
  • Defense
  • Deterrence
  • Intelligence
  • Launch
  • Strategy
  • Surveillance
  • Missile
  • Navigation
  • War
Font ResizerAa
Space Security NewsSpace Security News
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About Us
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About Us
    • Mission
    • Services
    • Contact Us
Follow US
© 2026 Space Security News. All Rights Reserved.
News

Flaws in NASA command console let anyone fire spacecraft commands

Critical flaws in NASA/JPL's AIT-GUI console allowed unauthenticated users to send commands to spacecraft.

By
SSN Staff
Last updated: August 24, 2026
2 Min Read
Share

NASA/JPL’s open-source spacecraft command console lacked working authentication on its state-changing endpoints, letting anyone who reached the port issue commands, researchers found.

Cycode’s researchers dug into AIT-GUI, the browser-based operator console of NASA/JPL’s open-source AMMOS Instrument Toolkit, and found its web server bound to every network interface on port 8080, ignoring the configured host setting.

No login, session gate or CSRF protection guarded routes including POST /cmd, which passes input straight to the command bus. A session cookie is handed out to any request for the root page, so an attacker can obtain one without credentials and send commands on a second request. Two other endpoints built filesystem paths from raw input, enabling traversal outside script and sequence directories.

The advisory GHSA-p9r8-2q67-fp86 rates the chain critical at CVSS 9.4. No CVE has been assigned. Because the routes accept form-encoded bodies that browsers treat as simple requests, a webpage an operator merely visits can deliver a cross-origin POST without preflight, the researchers said.

Cycode framed the impact bluntly: an unauthenticated command results in issued instrument commands, not a defaced page. Researcher Yuval Elbar called the console a web GUI that listens on every interface, asks nobody for a password and can be steered by any page an operator opens.

The flaws were fixed in AIT-GUI 2.5.2, released in mid-August, which binds the configured host, rejects cross-origin state changes and confines script and sequence endpoints to their roots. Cycode urged operators to upgrade and keep the port off untrusted networks.

TAGGED:AMMOSCycodeground segmentNASAsatellite securityspacecraft commandvulnerability
SOURCES:Security AffairsThe Hacker News

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print

LATEST NEWS

Unnamed defense customers reserve payload room on Dream Chaser’s first flight

News
September 5, 2026

Chinese satellite in a rare retrograde orbit leaves 43 tracked fragments

US tracking counts 43 fragments after a Chinese satellite in a rare retrograde orbit breaks…

September 5, 2026

France’s space summit loses its US heavyweights over White House warnings

SpaceX and Blue Origin lead US withdrawals from Macron's summit after Washington advises firms to…

September 5, 2026

The Space Force changes commanders as Schiess pledges deliberate growth

Gen. Douglas Schiess succeeds Chance Saltzman as chief of space operations with growth and deterrence…

September 5, 2026

YOU MAY ALSO LIKE

Five Eyes space teams convert threat intel into defensive tactics

US and Five Eyes coalition space operators met at Vandenberg Space Force Base to turn threat intelligence into orbital warfare…

News
August 2, 2026

SpaceX’s Starfall reentry vehicle gets FAA green light for test flights

New FAA filings confirm SpaceX’s Starfall capsule program is moving toward flight tests with dual-use implications for defense logistics and…

Ground Segment & OperationsNews
May 31, 2026

Pentagon picks three firms to clean up spent satellites

Three firms join the Pentagon's push to retire spent satellites instead of leaving them in graveyard orbits.

News
August 17, 2026

Air Force seizes control of troubled jam-proof GPS receiver project

The Air Force absorbed the Pentagon's M-code GPS receiver program from the Space Force after years of technical delays.

News
July 27, 2026

Breaking developments in space and cybersecurity, decoded for the modern defense and technology landscape.

Follow us: 

  • News
  • Features
  • Spotlight
  • Events
  • About Us
  • Mission
  • Services
  • Contact Us
Copyright © 2026 Space Security News. All Rights Reserved.
Privacy Policy | Legal
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?