CVE-2026-67979
9.1 CRITICALpublic exploit availablePublished 2026-08-04 · Updated 2026-08-05
AI risk analysis
- Summary
- This flaw allows attackers to execute arbitrary code by placing a shared object on target storage, due to incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1. This is a critical vulnerability that can lead to full system compromise.
- Exploitability
- Exploitation is relatively straightforward as attackers only need to place a shared object on target storage. The system must be running NASA cFS v7.0.1 without proper access controls in place.
- Blast radius
- If exploited, this vulnerability could result in full system compromise, allowing attackers to execute arbitrary code and potentially gain control over the entire system.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to NASA cFS v7.0.1 or later.
rcecode-execaccess-controlnasacfs
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary code via placing a shared object on target storage.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weaknesses
CWE-284
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-11381
- CRITICALCVE-2026-71268PoC
- HIGHCVE-2026-58197PoC
- CRITICALCVE-2026-76709
- HIGHCVE-2026-94036
- CRITICALCVE-2017-20241
- CRITICALCVE-2017-20242
- CRITICALCVE-2023-54399
Related by shared AI tags and CWE weakness class. Browse the full archive.