Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-71289: NASA-AMMOS ANMS Exposes Management API to the Internet

CVE-2026-71289 · published 1 month ago
Summary

A default configuration in NASA-AMMOS's Asynchronous Network Management System (ANMS) exposes its management API to the internet, allowing anyone to access sensitive information and send commands to connected devices. This affects NASA-AMMOS's reference implementation and a related toolset. To fix this, update the configuration to use the intended security gateway, which is the system's only authentication boundary.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
nasa-ammos anms <= *
Original advisory text
NASA-AMMOS ANMS / JHUAPL dtnma-tools Unauthenticated Remote Command Execution via Exposed AMP Manager REST API
The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service's REST API directly to the host network interface (port 8089, e.g. ":8089/tcp") with cap_add: NET_ADMIN, NET_RAW, SYS_NICE, bypassing the CAM (Configuration and Access Manager) gateway that is otherwise the system's sole authentication boundary.
Severity
9.8 Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published5 Aug 2026
Updated3 Sep 2026
First seen5 Aug 2026
Sources
CVE-2026-71289 · MITRE
Monitor software like this
Free during beta