CVE-2026-105105

LOWCVSS 9.8 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS AIT-Core through 3.1.1 allows an unauthenticated remote attacker with network access to the ZeroMQ message bus to inject spacecraft command data, exfiltrate command and telemetry traffic, inject forged telemetry, or disrupt the command and telemetry bus. The ait-server ZeroMQ broker binds its XSUB and XPUB sockets to all network interfaces by default without authentication or transport security. An attacker able to reach TCP port 5559 can publish messages onto internal topics, including the __commands__ command topic. With the shipped default configuration, command messages are forwarded through command_stream and emitted on the command-uplink UDP path. An attacker able to reach TCP port 5560 can subscribe to command and telemetry traffic on the ground bus. AIT-Core 3.1.2 changes the default ZeroMQ bind addresses to loopback.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-10-03: 310-03
Referenced assets3 URLs
Full discourse3 posts
  • Dark Web Intelligence@DailyDarkWeb

    🛰️🚨 CRITICAL NASA SPACECRAFT SOFTWARE FLAW ALLOWS UNAUTHENTICATED COMMAND INJECTION A critical vulnerability has been disclosed in: NASA AMMOS AIT-CORE CVE-2026-105105 CVSS: 9.8 AIT-Core is software used for spacecraft command and telemetry operations. The problem is unusually serious. Its core telemetry/command server exposes its ZeroMQ message bus on: 0.0.0.0 with NO authentication or transport security by default. An attacker who can reach TCP port 5559 can publish directly onto internal topics — including: __commands__ With the default configuration, those messages can travel through the command stream and reach the: SPACECRAFT COMMAND-UPLINK PATH. Potential impact: * Inject arbitrary spacecraft command data * Read real-time telemetry * Forge telemetry shown to operators * Manipulate monitoring/limit-check data * Disrupt the command and telemetry bus No credentials. No user interaction. No additional plugin required. The researcher demonstrated the issue live against AIT-Core 3.1.1 and published a working proof-of-concept. Affected: AIT-Core <= 3.1.1 Fixed: AIT-Core 3.1.2 The fix changes the ZeroMQ XSUB/XPUB interfaces from all network interfaces to: 127.0.0.1 There is currently NO evidence that CVE-2026-105105 has been exploited in the wild. ⚠️ Analyst Note: This is not "remote control of NASA spacecraft from the Internet." Network access to the vulnerable AIT server is still required. But the security boundary is remarkable: A system responsible for spacecraft command + telemetry could expose its internal message bus without authentication under its shipped default configuration. And the impact isn't merely server compromise. The vulnerable data path reaches the spacecraft command-uplink pipeline itself. Original NASA-AMMOS advisory + technical details: https://github.com/NASA-AMMOS/AIT-Core/security/advisories/GHSA-ccw5-g774-3683 #NASA #SpaceSecurity #CVE2026105105 #CyberSecurity #Vulnerability #ThreatIntel #DDW

    0201525.8K
    206.2K followersView on X
  • ExploitGrid@exploitgrid

    CVSS 9.8 flaw in NASA's AIT-Core exposes a critical security boundary. CVE-2026-105105 lets unauthenticated attackers with network access reach the ZeroMQ command/telemetry bus. Affected: ≤3.1.1 Fixed: 3.1.2 Full details: https://exploitgrid.net/vulnerabilities/CVE-2026-105105 #CyberSecurity #SpaceSecurity

    0002068
    355 followersView on X
  • CVE@CVEnew

    CVE-2026-105105 CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS AIT-Core through 3.1.1 allows a… https://www.cve.org/CVERecord?id=CVE-2026-105105

    00000816
    58.1K followersView on X

Explore more