---
id: CVE-2026-60112
title: AIT-GUI < 2.5.1 Missing Authentication via Sessions.create()
summary: >-
  AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing
  authentication vulnerability that allows any unauthenticated network attacker
  to obtain a valid session and issue arbitrary spacecraft commands by calling
  Sessions.create…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
cwe:
  - CWE-306
vendor: NASA-AMMOS
product: AIT-GUI
affected:
  - AIT-GUI < 2.5.1
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-07-29T17:57:49.185564Z'
published: '2026-07-29'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:20:08.573Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-60112'
references:
  - url: 'https://github.com/NASA-AMMOS/AIT-GUI/releases/tag/2.5.1'
    label: Release Notes
  - url: 'https://github.com/NASA-AMMOS/AIT-GUI/blob/2.5.1/CHANGELOG.md'
    label: Changelog
  - url: >-
      https://github.com/NASA-AMMOS/AIT-GUI/commit/beb8fc0813eded89f985d3eb9a73535dd327726d
    label: Patch Commit
  - url: >-
      https://www.vulncheck.com/advisories/ait-gui-missing-authentication-via-sessions-create
tags:
  - cve.org
epss: 0.00788
epssPercentile: 0.5457
ingestedAt: '2026-10-01T15:48:17.861Z'
---

## Overview

AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue arbitrary spacecraft commands by calling Sessions.create() without any credential check. Attackers can exploit the unauthenticated session issuance in Sessions.create() and subsequently invoke handle_cmd() to forward arbitrary commands directly to the AIT command bus without any authentication gate between session creation and command dispatch.

## Affected

- `AIT-GUI < 2.5.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
