What is CVE-2026-71289?
CVE-2026-71289 is a configuration vulnerability in the NASA-AMMOS ANMS reference implementation where the default docker-compose.yml publishes the amp-manager REST API directly to the host network interface and grants privileged Linux capabilities. This exposes the API to potential network-based attacks and increases the container's risk profile. It is recommended to isolate the API from the host network and remove unnecessary capabilities.
Azərbaycanca: CVE-2026-71289 NASA-AMMOS ANMS istinad tətbiqində aşkar edilmiş konfiqurasiya zəifliyidir. Standart docker-compose.yml faylı amp-manager REST API-ni host şəbəkə interfeysinə birbaşa yayımlayır və əlavə imtiyazlı Linux imkanları (cap_add: NET_ADMIN, NET_RAW, SYS_NICE) təmin edərək mühiti riskə atır. Bu API-ni şəbəkədən təcrid etmək və lazımsız imkanları silmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-1188
FAQ1
What exact configuration flaw does CVE-2026-71289 involve in NASA-AMMOS ANMS?
This vulnerability stems from the default docker-compose.yml publishing the amp-manager REST API directly to the host network interface and granting the container additional privileged Linux capabilities such as NET_ADMIN, NET_RAW, and SYS_NICE.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.