CVE-2026-79954: CWE-306 Missing Authentication for Critical Function in NASA CryptoLib
NASA CryptoLib version 1.5.0 has an authentication downgrade vulnerability in its Telecommand receive path. The vulnerability arises because the receiver selects the Security Association (SA) based only on the SPI field in the incoming frame without verifying that the SA is authorized for the frame's GVCID. This flaw can allow unauthorized use of critical functions due to missing authentication checks.
AI Analysis
Technical Summary
CVE-2026-79954 describes a missing authentication vulnerability (CWE-306) in NASA CryptoLib 1.5.0. Specifically, in the Telecommand receive path, the software selects the Security Association for Secure Data Link Services (SDLS) processing solely based on the Security Parameter Index (SPI) field of the incoming frame. However, it fails to verify that the selected SA is authorized for the frame's Global Virtual Channel Identifier (GVCID). This can lead to an authentication downgrade, potentially allowing unauthorized commands or data to be processed.
Potential Impact
The vulnerability has a high severity CVSS score of 8.7, indicating a significant risk. Because the authentication check is missing for critical functions, an attacker could exploit this flaw to bypass security controls in the Telecommand receive path, potentially leading to unauthorized command execution or data manipulation within NASA CryptoLib 1.5.0. No known exploits are reported in the wild at this time.
Mitigation Recommendations
No patch or official fix information is provided in the available data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should consider restricting access to the affected component and monitor for updates from NASA regarding a security patch or mitigation instructions.
CVE-2026-79954: CWE-306 Missing Authentication for Critical Function in NASA CryptoLib
Description
NASA CryptoLib version 1.5.0 has an authentication downgrade vulnerability in its Telecommand receive path. The vulnerability arises because the receiver selects the Security Association (SA) based only on the SPI field in the incoming frame without verifying that the SA is authorized for the frame's GVCID. This flaw can allow unauthorized use of critical functions due to missing authentication checks.
CVSS v4.0
Score 8.7high
Affected software
NASA
CryptoLib
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-79954 describes a missing authentication vulnerability (CWE-306) in NASA CryptoLib 1.5.0. Specifically, in the Telecommand receive path, the software selects the Security Association for Secure Data Link Services (SDLS) processing solely based on the Security Parameter Index (SPI) field of the incoming frame. However, it fails to verify that the selected SA is authorized for the frame's Global Virtual Channel Identifier (GVCID). This can lead to an authentication downgrade, potentially allowing unauthorized commands or data to be processed.
Potential Impact
The vulnerability has a high severity CVSS score of 8.7, indicating a significant risk. Because the authentication check is missing for critical functions, an attacker could exploit this flaw to bypass security controls in the Telecommand receive path, potentially leading to unauthorized command execution or data manipulation within NASA CryptoLib 1.5.0. No known exploits are reported in the wild at this time.
Mitigation Recommendations
No patch or official fix information is provided in the available data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should consider restricting access to the affected component and monitor for updates from NASA regarding a security patch or mitigation instructions.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Fluid Attacks
- Date Reserved
- 2026-08-25T15:27:48.157Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aac949555bf5e2cf551bcad
Added to database: 09/18/2026, 01:32:05 UTC
Last enriched: 09/18/2026, 01:46:29 UTC
Last updated: 09/18/2026, 02:09:59 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.