Skip to main content

CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS AIT-Core… (CVE-2026-105105)

0
Critical
Published: 10/03/2026 (10/03/2026, 12:31:29 UTC)
Source: GCVE Database

Description

CVE-2026-105105 is a critical vulnerability in the NASA-AMMOS AIT-Core ait.core.server telemetry and command broker (ait-server) through version 3.1.1. It allows unauthenticated remote attackers with network access to the ZeroMQ message bus to inject spacecraft command data, exfiltrate command and telemetry traffic, inject forged telemetry, or disrupt the command and telemetry bus. The vulnerability arises because the ait-server ZeroMQ broker binds its XSUB and XPUB sockets to all network interfaces by default without authentication or transport security. Version 3.1.2 mitigates this by changing the default ZeroMQ bind addresses to loopback.

CVSS v3.1

Score 9.8critical

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected software

GitHub Actionsmore threats →ai
nasa-ammos/AIT-Core
pkg:github/nasa-ammos/AIT-Core
Affected versions
<=3.1.1

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/03/2026, 17:23:35 UTC

Technical Analysis

The vulnerability identified as CWE-306 (Missing Authentication for Critical Function) affects the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS AIT-Core versions up to 3.1.1. The ZeroMQ broker binds XSUB and XPUB sockets to all network interfaces by default without authentication or encryption. This allows an unauthenticated attacker with network access to TCP port 5559 to publish messages on internal topics, including the critical __commands__ topic, potentially injecting spacecraft commands. Additionally, access to TCP port 5560 allows subscription to command and telemetry traffic, enabling data exfiltration or injection of forged telemetry. The default configuration forwards command messages through command_stream and emits them on the command-uplink UDP path. The issue is addressed in AIT-Core 3.1.2 by restricting ZeroMQ bind addresses to loopback, preventing remote network access.

Potential Impact

An unauthenticated remote attacker with network access to the ZeroMQ message bus can inject unauthorized spacecraft commands, exfiltrate sensitive command and telemetry data, inject forged telemetry data, or disrupt the command and telemetry communication bus. This can lead to full compromise of spacecraft command and telemetry operations, representing a critical impact on confidentiality, integrity, and availability.

Mitigation Recommendations

A fix is available in AIT-Core version 3.1.2, which changes the default ZeroMQ bind addresses to loopback, effectively preventing remote network access to the message bus. Users should upgrade to version 3.1.2 or later to mitigate this vulnerability. No other mitigations are indicated in the advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-9xfm-37f4-2h8g
Osv Schema Version
1.4.0
Aliases
["CVE-2026-105105"]
Database Specific Severity
CRITICAL
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6ac13969a43b0b3b89d5fbad

Added to database: 10/03/2026, 17:20:41 UTC

Last enriched: 10/03/2026, 17:23:35 UTC

Last updated: 10/03/2026, 21:45:56 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses