CVE-2026-67975
Received Received - Intake

Incorrect Access Control in NASA cFS v7.0.1

Vulnerability report for CVE-2026-67975, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: MITRE

Description

Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TO_LAB add/remove subscription commands.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-04
AI Q&A
2026-08-04
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
nasa cfs 7.0.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an incorrect access control issue in NASA cFS v7.0.1. It allows attackers to manipulate subscription commands by sending TO_LAB add or remove subscription commands. This can lead to unauthorized removal of low-index subscriptions and addition of new streams.

Impact Analysis

An attacker could exploit this to disrupt system operations by removing critical subscriptions or adding unauthorized streams. This may cause unexpected behavior, data loss, or unauthorized access to system functions depending on the affected cFS deployment.

Mitigation Strategies

Immediately restrict access to TO_LAB add/remove subscription commands and review subscription configurations for unauthorized changes. Ensure cFS v7.0.1 is updated to a patched version if available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-67975. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart