{"id":"CVE-2026-67979","published":"2026-08-04T21:16:37.360","lastModified":"2026-08-05T20:17:14.190","description":"Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary code via placing a shared object on target storage.","cvssScore":9.1,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","cwes":["CWE-284"],"vendors":[],"products":[],"references":[{"url":"https://github.com/nasa/cFS/issues/1057","tags":[]},{"url":"https://github.com/nasa/cFS/issues/1057","tags":[]}],"exploitRefs":[{"url":"https://github.com/nasa/cFS/issues/1057","tags":[]},{"url":"https://github.com/nasa/cFS/issues/1057","tags":[]}],"hasPoc":true,"ai":{"summary":"This flaw allows attackers to execute arbitrary code by placing a shared object on target storage, due to incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1. This is a critical vulnerability that can lead to full system compromise.","exploitability":"Exploitation is relatively straightforward as attackers only need to place a shared object on target storage. The system must be running NASA cFS v7.0.1 without proper access controls in place.","blast_radius":"If exploited, this vulnerability could result in full system compromise, allowing attackers to execute arbitrary code and potentially gain control over the entire system.","remediation":"Upgrade to NASA cFS v7.0.1 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","code-exec","access-control","nasa","cfs"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T09:11:33.813Z"}}