CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS AIT-Core… (CVE-2026-105105)
CVE-2026-105105 is a critical vulnerability in the NASA-AMMOS AIT-Core ait.core.server telemetry and command broker (ait-server) through version 3.1.1. It allows unauthenticated remote attackers with network access to the ZeroMQ message bus to inject spacecraft command data, exfiltrate command and telemetry traffic, inject forged telemetry, or disrupt the command and telemetry bus. The vulnerability arises because the ait-server ZeroMQ broker binds its XSUB and XPUB sockets to all network interfaces by default without authentication or transport security. Version 3.1.2 mitigates this by changing the default ZeroMQ bind addresses to loopback.
AI Analysis
Technical Summary
The vulnerability identified as CWE-306 (Missing Authentication for Critical Function) affects the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS AIT-Core versions up to 3.1.1. The ZeroMQ broker binds XSUB and XPUB sockets to all network interfaces by default without authentication or encryption. This allows an unauthenticated attacker with network access to TCP port 5559 to publish messages on internal topics, including the critical __commands__ topic, potentially injecting spacecraft commands. Additionally, access to TCP port 5560 allows subscription to command and telemetry traffic, enabling data exfiltration or injection of forged telemetry. The default configuration forwards command messages through command_stream and emits them on the command-uplink UDP path. The issue is addressed in AIT-Core 3.1.2 by restricting ZeroMQ bind addresses to loopback, preventing remote network access.
Potential Impact
An unauthenticated remote attacker with network access to the ZeroMQ message bus can inject unauthorized spacecraft commands, exfiltrate sensitive command and telemetry data, inject forged telemetry data, or disrupt the command and telemetry communication bus. This can lead to full compromise of spacecraft command and telemetry operations, representing a critical impact on confidentiality, integrity, and availability.
Mitigation Recommendations
A fix is available in AIT-Core version 3.1.2, which changes the default ZeroMQ bind addresses to loopback, effectively preventing remote network access to the message bus. Users should upgrade to version 3.1.2 or later to mitigate this vulnerability. No other mitigations are indicated in the advisory.
CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS AIT-Core… (CVE-2026-105105)
Description
CVE-2026-105105 is a critical vulnerability in the NASA-AMMOS AIT-Core ait.core.server telemetry and command broker (ait-server) through version 3.1.1. It allows unauthenticated remote attackers with network access to the ZeroMQ message bus to inject spacecraft command data, exfiltrate command and telemetry traffic, inject forged telemetry, or disrupt the command and telemetry bus. The vulnerability arises because the ait-server ZeroMQ broker binds its XSUB and XPUB sockets to all network interfaces by default without authentication or transport security. Version 3.1.2 mitigates this by changing the default ZeroMQ bind addresses to loopback.
CVSS v3.1
Score 9.8critical
Affected software
pkg:github/nasa-ammos/AIT-CoreRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability identified as CWE-306 (Missing Authentication for Critical Function) affects the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS AIT-Core versions up to 3.1.1. The ZeroMQ broker binds XSUB and XPUB sockets to all network interfaces by default without authentication or encryption. This allows an unauthenticated attacker with network access to TCP port 5559 to publish messages on internal topics, including the critical __commands__ topic, potentially injecting spacecraft commands. Additionally, access to TCP port 5560 allows subscription to command and telemetry traffic, enabling data exfiltration or injection of forged telemetry. The default configuration forwards command messages through command_stream and emits them on the command-uplink UDP path. The issue is addressed in AIT-Core 3.1.2 by restricting ZeroMQ bind addresses to loopback, preventing remote network access.
Potential Impact
An unauthenticated remote attacker with network access to the ZeroMQ message bus can inject unauthorized spacecraft commands, exfiltrate sensitive command and telemetry data, inject forged telemetry data, or disrupt the command and telemetry communication bus. This can lead to full compromise of spacecraft command and telemetry operations, representing a critical impact on confidentiality, integrity, and availability.
Mitigation Recommendations
A fix is available in AIT-Core version 3.1.2, which changes the default ZeroMQ bind addresses to loopback, effectively preventing remote network access to the message bus. Users should upgrade to version 3.1.2 or later to mitigate this vulnerability. No other mitigations are indicated in the advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-9xfm-37f4-2h8g
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-105105"]
- Database Specific Severity
- CRITICAL
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac13969a43b0b3b89d5fbad
Added to database: 10/03/2026, 17:20:41 UTC
Last enriched: 10/03/2026, 17:23:35 UTC
Last updated: 10/03/2026, 21:45:56 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.