Overview
A critical missing-authentication vulnerability has been disclosed in AIT-Core, the open-source spacecraft Ground Data System (GDS) toolkit maintained by NASA's AMMOS (Advanced Multi-Mission Operations System) program. Tracked as CVE-2026-105105 and classified under CWE-306 (Missing Authentication for Critical Function), the flaw sits in ait.core.server, the telemetry and command broker component known as ait-server.
The broker relies on ZeroMQ message-bus sockets to move command and telemetry traffic between ground-system components. In the shipped default configuration, those sockets bind to all network interfaces rather than loopback, and no authentication or transport security is enforced. Any attacker with network access to the broker's ports can subscribe to live command/telemetry traffic or publish directly onto internal topics — including the command topic itself.
AIT-Core is used by mission teams and ground-system integrators building command-and-control software for spacecraft and instrument operations, making this a rare case of a critical web/network-style vulnerability with a direct path into spacecraft command infrastructure.
Technical Details
| Field | Value |
|---|---|
| CVE ID | CVE-2026-105105 |
| CWE | CWE-306: Missing Authentication for Critical Function |
| Severity | Critical |
| CVSS 3.1 Score | 9.8 |
| CVSS Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Attack Vector | Network (ZeroMQ broker ports) |
| Authentication | None Required |
| Privileges Required | None |
| User Interaction | None |
| Affected Software | AIT-Core ≤ 3.1.1 |
| Fixed Version | AIT-Core 3.1.2 |
How It Works
The ait-server broker exposes two ZeroMQ sockets by default:
- Port 5560 (XPUB/subscriber-facing) — an attacker who can reach this port can subscribe to the ground bus, reading live command and telemetry traffic as it passes through the broker.
- Port 5559 (XSUB/publisher-facing) — an attacker who can reach this port can publish messages onto internal topics, including the
__commands__command topic. With the default configuration, messages published here are forwarded throughcommand_streamand ultimately emitted on the command-uplink path.
Because neither socket requires authentication, TLS, or any form of access control, the vulnerability reduces to a basic network-reachability problem: whoever can route packets to ports 5559/5560 can read and write to the spacecraft command and telemetry bus as if they were a trusted ground-system component.
NASA-AMMOS fixed the issue in AIT-Core 3.1.2, which changes the default ZeroMQ bind addresses from all-interfaces to loopback only, removing the unauthenticated network exposure by default.
Impact Assessment
| Impact Area | Description |
|---|---|
| Command Injection | Attacker can inject forged spacecraft/instrument command data onto the uplink path |
| Telemetry Exfiltration | Attacker can passively read all command and telemetry traffic transiting the broker |
| Telemetry Spoofing | Attacker can inject forged telemetry into downstream consumers (dashboards, automation, decision systems) |
| Availability | Attacker can flood or disrupt the ZeroMQ bus, denying legitimate command/telemetry flow |
| Operational Risk | For live mission ground systems, successful exploitation could affect spacecraft or instrument commanding integrity |
Who Is At Risk
Any organization running ait-server from AIT-Core versions 3.1.1 or earlier with the default bind configuration is exposed if the broker's ports are reachable from an untrusted network. Realistic exposure scenarios include:
- Ground-system test beds or integration environments where the broker was deployed without an additional network boundary
- Multi-tenant or shared mission-operations infrastructure where other tenants/VLANs can reach the broker
- Any deployment where "internal network" assumptions turned out to be broader than intended (flat networks, misconfigured firewalls, cloud security groups left open)
Flight-operational ground systems that are properly air-gapped or restricted to isolated operational networks have a much smaller practical attack surface, but should still patch — defense in depth, not network isolation alone, is the correct posture for a bus carrying command authority.
Mitigation
Immediate Actions
- Upgrade to AIT-Core 3.1.2 or later, which binds the ZeroMQ broker to loopback by default.
- If upgrading immediately isn't possible, restrict network access to TCP ports 5559 and 5560 via host firewall rules, security groups, or network ACLs so only trusted ground-system hosts can reach the broker.
- Audit current bind configuration on any running
ait-serverinstance to confirm whether it is listening on0.0.0.0(all interfaces) rather than127.0.0.1.
For Mission and Ground-System Operators
- Treat the AIT-Core broker as part of the command authority chain — apply the same network segmentation rigor used for other command-path infrastructure, not general IT-network assumptions.
- Add egress/ingress monitoring on ports 5559/5560 to detect unexpected connection attempts from outside the ground-system network.
- Review any test or integration environments that may have inherited production-like configurations without production-like network controls.
For Security Teams Supporting Space/Aerospace Infrastructure
- Add AIT-Core to vulnerability inventories for any mission ground-system software bill of materials (SBOM) — this component is easy to overlook since it is infrastructure tooling rather than flight software.
- Validate that patch management for ground-system GDS components follows the same cadence as other critical infrastructure, given the direct line from this bug to command-path integrity.
Key Takeaways
- CVE-2026-105105 is a CVSS 9.8 missing-authentication flaw in NASA-AMMOS AIT-Core's
ait-serverZeroMQ broker, affecting versions ≤ 3.1.1. - The broker's command (port 5559) and telemetry (port 5560) sockets bind to all interfaces with no authentication by default.
- A network-adjacent, unauthenticated attacker can inject spacecraft commands, exfiltrate telemetry, spoof telemetry, or disrupt the bus.
- AIT-Core 3.1.2 fixes the issue by defaulting the broker to loopback-only binding.
- As of disclosure, there is no public proof-of-concept exploit and the flaw is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog — but the low attack complexity and critical impact warrant prompt patching.
- Network segmentation around ground-system infrastructure should not be the only control — upgrade and apply firewall restrictions even on networks assumed to be trusted.