CVE-2026-71289: NASA-AMMOS ANMS / JHUAPL dtnma-tools Unauthenticated Remote Command Execution via Exposed AMP Manager REST API
The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service's REST API directly to the host network interface (port 8089, e.g. ":8089/tcp") with capadd: NETADMIN, NETRAW, SYSNICE, bypassing the CAM (Configuration and Access Manager) gateway that is otherwise the system's sole authentication boundary.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-71289?
CVE-2026-71289 has a severity rating of 9.8, classified as critical.
How do I fix CVE-2026-71289?
To fix CVE-2026-71289, restrict access to the amp-manager REST API and avoid exposing it directly to the host network interface.
What type of vulnerability is CVE-2026-71289?
CVE-2026-71289 is an unauthenticated remote command execution vulnerability.
What systems are affected by CVE-2026-71289?
CVE-2026-71289 affects the NASA-AMMOS Asynchronous Network Management System and JHUAPL dtnma-tools.
What risks are associated with CVE-2026-71289?
CVE-2026-71289 poses risks of unauthorized access and execution of commands on affected systems.