Critical severity9.8NVD Advisory· Published Aug 5, 2026· Updated Aug 26, 2026
CVE-2026-71289
CVE-2026-71289
Description
The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service's REST API directly to the host network interface (port 8089, e.g. ":8089/tcp") with cap_add: NET_ADMIN, NET_RAW, SYS_NICE, bypassing the CAM (Configuration and Access Manager) gateway that is otherwise the system's sole authentication boundary.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
News mentions
1- NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft CommandsThe Hacker News · Aug 20, 2026