Description
Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TO_LAB add/remove subscription commands.
Published: 2026-08-03
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

NASA’s core Flight System (cFS) version 7.0.1 contains an incorrect access‑control flaw that permits an attacker to send TO_LAB add or remove subscription commands and arbitrarily delete low‑index subscriptions or create new telemetry streams. This flaw enables a remote adversary to disrupt mission telemetry by dropping legitimate streams or injecting unauthorized ones, potentially leading to loss of critical data, degraded situational awareness, or denial of service for downstream systems that rely on those streams.

Affected Systems

The vulnerability is confined to NASA’s core Flight System version 7.0.1, an open‑source software platform used in spaceflight and aeronautics applications. No other vendors, products or version ranges are currently reported as affected.

Risk and Exploitability

The flaw arises from a lack of proper authorization checks in the subscription handling component. An attacker who can reach the cFS command interface can exploit the weakness without needing elevated privileges or additional credentials. Given the CVSS score of 7.5 and an EPSS score of <1%, exploitation likelihood remains low but the control of telemetry streams is a critical capability, and the vulnerability is not yet in CISA’s KEV catalog. The attack vector is inferred to be remote command injection over the cFS communication link, requiring network connectivity to the spacecraft or ground segment that hosts the cFS instance.

Generated by OpenCVE AI on August 12, 2026 at 00:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check NASA’s cFS repository for an updated release that fixes the access‑control issue and apply the patch to version 7.0.1.
  • Disable or restrict TO_LAB add/remove subscription commands to trusted users or networks, and enforce strict authentication for any command that alters subscriptions.
  • Implement network segmentation or firewall rules to limit external access to the cFS command interface and monitor logs for unexpected subscription changes.

Generated by OpenCVE AI on August 12, 2026 at 00:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title cFS Unauthorized Telemetry Stream Modification

Tue, 04 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Nasa
Nasa cfs
Vendors & Products Nasa
Nasa cfs

Mon, 03 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TO_LAB add/remove subscription commands.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-06T15:38:05.561Z

Reserved: 2026-07-30T00:00:00.000Z

Link: CVE-2026-67975

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-03T22:16:51.613

Modified: 2026-08-06T22:18:24.197

Link: CVE-2026-67975

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T00:15:12Z

Weaknesses