CVE-2026-67975: High severity nasa cFS vulnerability
Published Aug 3, 2026
·Updated
Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TOLAB add/remove subscription commands.
Affected Software
1 affected component
nasa cFS=7.0.1
Event History
Aug 3, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-67975?
CVE-2026-67975 has a risk score of 45, indicating a moderate severity level.
2
How can I fix CVE-2026-67975?
To mitigate CVE-2026-67975, update NASA cFS to the latest version that addresses the access control vulnerabilities.
3
What software is affected by CVE-2026-67975?
CVE-2026-67975 affects NASA cFS version 7.0.1.
4
What type of vulnerability is CVE-2026-67975?
CVE-2026-67975 is classified as an incorrect access control vulnerability.
5
What kind of attacks can exploit CVE-2026-67975?
CVE-2026-67975 can be exploited by attackers to arbitrarily remove low-index subscriptions and add new streams via specific commands.