{"id":"CVE-2026-67979","published":"2026-08-04T21:16:37.360","lastModified":"2026-08-05T20:17:14.190","description":"Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary code via placing a shared object on target storage.","cvssScore":9.1,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","cwes":["CWE-284"],"vendors":[],"products":[],"references":[{"url":"https://github.com/nasa/cFS/issues/1057","tags":[]},{"url":"https://github.com/nasa/cFS/issues/1057","tags":[]}],"exploitRefs":[{"url":"https://github.com/nasa/cFS/issues/1057","tags":[]},{"url":"https://github.com/nasa/cFS/issues/1057","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows attackers to execute arbitrary code by placing a shared object on target storage due to incorrect access control in NASA cFS v7.0.1's dynamic application start path component.","exploitability":"Exploitation requires placing a malicious shared object on the target storage, which could be feasible if proper file system protections are not in place.","blast_radius":"If exploited, this vulnerability could lead to full compromise of the affected system, potentially allowing unauthorized execution of code with high impact.","remediation":"Update to the latest version of NASA cFS that addresses this issue or apply vendor-provided patches immediately.","tags":["rce","code-execution","patch-required"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:44:34.132Z"}}