Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-71289: NASA-AMMOS ANMS Exposes Management API to the Internet
CVE-2026-71289 · published 1 month ago
Summary
A default configuration in NASA-AMMOS's Asynchronous Network Management System (ANMS) exposes its management API to the internet, allowing anyone to access sensitive information and send commands to connected devices. This affects NASA-AMMOS's reference implementation and a related toolset. To fix this, update the configuration to use the intended security gateway, which is the system's only authentication boundary.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| nasa-ammos | anms | <= * |
Original advisory text
NASA-AMMOS ANMS / JHUAPL dtnma-tools Unauthenticated Remote Command Execution via Exposed AMP Manager REST API
The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service's REST API directly to the host network interface (port 8089, e.g. ":8089/tcp") with cap_add: NET_ADMIN, NET_RAW, SYS_NICE, bypassing the CAM (Configuration and Access Manager) gateway that is otherwise the system's sole authentication boundary.
Severity
9.8
Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published5 Aug 2026
Updated3 Sep 2026
First seen5 Aug 2026
Monitor software like this
Free during beta