CVE-2026-105105

Source
https://cve.org/CVERecord?id=CVE-2026-105105
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105105.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-105105
Related
Published
2026-10-03T11:55:44Z
Modified
2026-10-06T02:56:42Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Unauthenticated ZeroMQ command/telemetry bus in AIT-Core allows remote spacecraft command injection and telemetry exfiltration
Details

CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS AIT-Core through 3.1.1 allows an unauthenticated remote attacker with network access to the ZeroMQ message bus to inject spacecraft command data, exfiltrate command and telemetry traffic, inject forged telemetry, or disrupt the command and telemetry bus. The ait-server ZeroMQ broker binds its XSUB and XPUB sockets to all network interfaces by default without authentication or transport security. An attacker able to reach TCP port 5559 can publish messages onto internal topics, including the commands command topic. With the shipped default configuration, command messages are forwarded through command_stream and emitted on the command-uplink UDP path. An attacker able to reach TCP port 5560 can subscribe to command and telemetry traffic on the ground bus. AIT-Core 3.1.2 changes the default ZeroMQ bind addresses to loopback.

Database specific
{
    "cna_assigner":  "TuranSec",
    "cwe_ids":  [
        "CWE-306"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105105.json"
}
References

Affected packages

Git / github.com/nasa-ammos/ait-core

Affected ranges

Type
GIT
Repo
https://github.com/nasa-ammos/ait-core
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "last_affected":  "3.1.1"
        },
        {
            "fixed":  "3.1.1"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

2.*
2.0.0
2.0.1
2.0rc1.dev0
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6-rc1
2.4.0
2.5.0
2.5.1
2.5.2
3.*
3.0.0-rc1
3.1.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105105.json"