CVE-2026-71289

critical

Description

The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service's REST API directly to the host network interface (port 8089, e.g. ":8089/tcp") with cap_add: NET_ADMIN, NET_RAW, SYS_NICE, bypassing the CAM (Configuration and Access Manager) gateway that is otherwise the system's sole authentication boundary.

References

https://thehackernews.com/2026/08/nasa-ait-gui-flaws-could-let.html

https://github.com/sm-ard/devops-pulse

https://github.com/NASA-AMMOS/anms

https://github.com/JHUAPL-DTNMA/dtnma-tools

Details

Source: Mitre, NVD

Published: 2026-08-05

Updated: 2026-08-26

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.00369