Description
Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary code via placing a shared object on target storage.
Published: 2026-08-04
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

NASA core Flight System (cFS) v7.0.1 contains an incorrect access control flaw in the Executive Services dynamic application start path component. The flaw permits an attacker to place a malicious shared object in a designated storage location, causing the system to load and execute the object. The result is arbitrary code execution on the target platform, potentially compromising confidentiality, integrity, and availability. The weakness maps to the category of improper authorization and controls.

Affected Systems

This vulnerability affects the NASA core Flight System (cFS) version 7.0.1. No other versions or products are listed; thus only installations of cFS 7.0.1 are impacted. The specific component is the dynamic application start path inside Executive Services, which determines where shared objects are loaded.

Risk and Exploitability

The CVSS score is not provided, but the description indicates a severe remote code execution risk. The EPSS score is not available, and the vulnerability is not in the CISA KEV catalog. With no published patch, exploitation would require an attacker to have write access to the storage location used by the dynamic application loader. The likely attack vector is via any mechanism that grants the attacker the ability to drop a shared object into that path, followed by an exploit of the loader to execute it.

Generated by OpenCVE AI on August 4, 2026 at 22:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Restrict filesystem permissions on the dynamic application start path so that only trusted system processes can write to it
  • Audit the storage location for unexpected shared objects and remove any that are not part of the official deployment
  • Configure file integrity monitoring or automated alerts to detect unauthorized modifications to the directory

Generated by OpenCVE AI on August 4, 2026 at 22:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 04 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Title Access Control Bypass Allows Arbitrary Code Execution in NASA cFS
Weaknesses CWE-284

Tue, 04 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary code via placing a shared object on target storage.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-04T20:58:25.753Z

Reserved: 2026-07-30T00:00:00.000Z

Link: CVE-2026-67979

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T22:45:03Z

Weaknesses