← Back

Wire · technology

NASA Ground Control Software Flaw Enables Unauthenticated Commands

Published

18 August 2026

Topic

technology

Sectors

Government & Space

Geography

United States

Source

Read at infosecurity-magazine.com

Verified

Fusion42 · 18 August 2026 · Fusion42 review

A critical vulnerability in NASA's open-source AMMOS Instrument Toolkit (AIT)-GUI ground control software allowed unauthenticated attackers to send spacecraft commands and execute scripts, enabling potential remote compromise through operators' browsers without proper authentication or CSRF protection. The issue has been fixed in version 2.5.2 after disclosure.

This Wire brief sits within Fusion42's coverage of Government & Space. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.

◆ The Wire takeaway

Your space or defence software must not trust operator interfaces by default. This flaw shows NASA ground control tools can be hijacked remotely through browsers. Patch early and isolate control surfaces to protect operational command chains.

Related on Wire

Topics

Government & Spacenasavulnerabilityspace-techsoftware-securityopen-sourcecybersecurity
NASA Ground Control Software Flaw Enables Unauthentic… | Fusion42