CVE-2026-60113: AIT-DSN < 2.2.2 Missing Authentication via SLE API Routes
AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager that allows unauthenticated network attackers to access seven unprotected API routes by sending direct HTTP requests with no credentials. Attackers can reach the exposed SLE endpoints to start or stop Deep Space Network communication sessions, retrieve telemetry frame data, and inject arbitrary frames into active spacecraft links.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60113?
CVE-2026-60113 has a critical severity rating of 9.3.
How do I fix CVE-2026-60113?
To fix CVE-2026-60113, upgrade to version 2.2.2 or later of the AIT-DSN software.
What type of vulnerability is CVE-2026-60113?
CVE-2026-60113 is a missing authentication vulnerability in the SLE API routes.
What impact does CVE-2026-60113 have?
CVE-2026-60113 allows unauthenticated attackers to access unprotected API routes.
What software is affected by CVE-2026-60113?
CVE-2026-60113 affects the AIT-DSN AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before version 2.2.2.