← Back to search

CVE-2026-67979

9.1 CRITICALpublic exploit available

Published 2026-08-04 · Updated 2026-08-05

AI risk analysis

Summary
This flaw allows attackers to execute arbitrary code by placing a shared object on target storage, due to incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1. This is a critical vulnerability that can lead to full system compromise.
Exploitability
Exploitation is relatively straightforward as attackers only need to place a shared object on target storage. The system must be running NASA cFS v7.0.1 without proper access controls in place.
Blast radius
If exploited, this vulnerability could result in full system compromise, allowing attackers to execute arbitrary code and potentially gain control over the entire system.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to NASA cFS v7.0.1 or later.
rcecode-execaccess-controlnasacfs

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary code via placing a shared object on target storage.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Weaknesses

CWE-284

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.