Description
Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary code via placing a shared object on target storage.
Published: 2026-08-04
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

NASA core Flight System (cFS) v7.0.1 contains an incorrect access control flaw in the Executive Services dynamic application start path component. The flaw permits an attacker to place a malicious shared object in a designated storage location, causing the system to load and execute the object. The result is arbitrary code execution on the target platform, potentially compromising confidentiality, integrity, and availability. The weakness maps to the category of improper authorization and controls.

Affected Systems

This vulnerability affects the NASA core Flight System (cFS) version 7.0.1. No other versions or products are listed; thus only installations of cFS 7.0.1 are impacted. The specific component is the dynamic application start path inside Executive Services, which determines where shared objects are loaded.

Risk and Exploitability

The CVSS score of 9.1 indicates a severe remote code execution risk. The EPSS score <1% and the vulnerability is not in the CISA KEV catalog. With no published patch, exploitation would require an attacker to have write access to the storage location used by the dynamic application loader. The likely attack vector is via any mechanism that grants the attacker the ability to drop a shared object into that path, followed by an exploit of the loader to execute it.

Generated by OpenCVE AI on August 5, 2026 at 20:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Restrict filesystem permissions on the dynamic application start path so that only trusted system processes can write to it
  • Audit the storage location for unexpected shared objects and remove any that are not part of the official deployment
  • Configure file integrity monitoring or automated alerts to detect unauthorized modifications to the directory

Generated by OpenCVE AI on August 5, 2026 at 20:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 05 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title Access Control Bypass Allows Arbitrary Code Execution in NASA cFS

Wed, 05 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Nasa
Nasa cfs
Vendors & Products Nasa
Nasa cfs

Tue, 04 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Title Access Control Bypass Allows Arbitrary Code Execution in NASA cFS
Weaknesses CWE-284

Tue, 04 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary code via placing a shared object on target storage.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-05T19:07:04.503Z

Reserved: 2026-07-30T00:00:00.000Z

Link: CVE-2026-67979

cve-icon Vulnrichment

Updated: 2026-08-05T19:06:57.926Z

cve-icon NVD

Status : Received

Published: 2026-08-04T21:16:37.360

Modified: 2026-08-05T20:17:14.190

Link: CVE-2026-67979

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T20:30:06Z

Weaknesses