What is CVE-2026-72577?
Multiple vulnerabilities in NASA fprime-gds up to version 3.4.3 allow an unauthenticated remote attacker to achieve remote code execution on the ground station host and inject arbitrary commands to connected spacecraft. These flaws stem from unauthenticated endpoints within the Flask application.
Azərbaycanca: NASA-nın fprime-gds (3.4.3 versiyasına qədər) alətində autentifikasiya olunmamış uzaqdan hücumçulara həm yer stansiyası hostunda ixtiyari kod icrası, həm də peyklərə əmr inyeksiyası imkanı verən çoxsaylı zəifliklər aşkarlanıb. Flask tətbiqində autentifikasiyanın olmaması kritik risk yaradır.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which NASA tool is affected by CVE-2026-72577?
NASA's fprime-gds tool, specifically versions up to 3.4.3, is affected.
What is the root cause of the CVE-2026-72577 vulnerability?
The root cause is the presence of unauthenticated endpoints within the Flask application, creating a critical risk.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.