Wire · technology
Critical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed ...
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 22 August 2026 · Fusion42 review
A critical vulnerability in NASA/JPL's open-source AIT-GUI spacecraft command software allowed unauthenticated actors to send commands to spacecraft instruments, with no authentication, session checks, or CSRF protection on key state-changing endpoints. The flaw was rated critical and has been fixed in version 2.5.2, with urgent recommendations to upgrade and audit exposed systems.
This Wire brief sits within Fusion42's coverage of Government & Space.
◆ ◆ The Wire takeaway
Your space mission software needs urgent security fixes to avoid command hijacking risks. Applying patches and locking down access now will protect your operations from remote attacks exploiting these common web flaws.
◆ Coverage
1 source · 22 Aug 2026
◆ Related on Wire
◆ Topics