PatchSiren cyber security CVE debrief
CVE-2026-105105 NASA-AMMOS CVE debrief
CVE-2026-105105 is a critical vulnerability in NASA-AMMOS AIT-Core through version 3.1.1, allowing an unauthenticated remote attacker to inject spacecraft command data, exfiltrate command and telemetry traffic, inject forged telemetry, or disrupt the command and telemetry bus. The vulnerability exists due to the ait-server ZeroMQ broker binding its XSUB and XPUB sockets to all network interfaces by default without authentication or transport security.
- Vendor
- NASA-AMMOS
- Product
- AIT-Core
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-03
- Original CVE updated
- 2026-10-03
- Advisory published
- 2026-10-03
- Advisory updated
- 2026-10-03
Who should care
Defenders responsible for systems with network access to TCP ports 5559 and 5560, especially those using NASA-AMMOS AIT-Core, should assess exposure and verify remediation. This includes operators managing affected deployments, platform administrators, vulnerability management teams, and security teams that need to prioritize and track remediation efforts.
Why it matters
CVE-2026-105105 is a critical vulnerability in NASA-AMMOS AIT-Core, allowing an unauthenticated remote attacker to inject spacecraft command data, exfiltrate command and telemetry traffic, inject forged telemetry, or disrupt the command and telemetry bus. Defenders should assess exposure and verify remediation, especially for systems with network access to TCP ports 5559 and 5560.
- Potential injection of spacecraft command data
- Exfiltration of command and telemetry traffic
- Injection of forged telemetry data
- Disruption of command and telemetry bus
Technical summary
The ait-server ZeroMQ broker in NASA-AMMOS AIT-Core through version 3.1.1 binds its XSUB and XPUB sockets to all network interfaces by default without authentication or transport security. This allows an unauthenticated remote attacker with network access to the ZeroMQ message bus to inject spacecraft command data, exfiltrate command and telemetry traffic, inject forged telemetry, or disrupt the command and telemetry bus.
Defensive priority
High priority for defenders to assess exposure and verify remediation, especially for systems with network access to TCP ports 5559 and 5560.
Recommended defensive actions
- Assess exposure by verifying network access to TCP ports 5559 and 5560
- Verify current version of AIT-Core and check for updates
- Implement authentication and transport security for ZeroMQ broker
- Monitor command and telemetry traffic for suspicious activity
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The vulnerability is confirmed in AIT-Core through version 3.1.1. Version 3.1.2 changes the default ZeroMQ bind addresses to loopback, mitigating the vulnerability. However, the supplied corpus does not provide information on all potentially affected versions or configurations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105105 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105105
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105105 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105105
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/Mothra-1
309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c
-
Source reference
Unverified legacy reference
URL: https://github.com/NASA-AMMOS/AIT-Core/
309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c
-
Source reference
Unverified legacy reference
URL: https://github.com/NASA-AMMOS/AIT-Core/security/advisories/GHSA-ccw5-g774-3683
309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c
-
Source reference
Unverified legacy reference
URL: https://github.com/advisories/GHSA-3j6g-pxmx-58qg
309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.