CVE-2026-67979
9.1 CRITICALpublic exploit availablePublished 2026-08-04 · Updated 2026-08-05
AI risk analysis
- Summary
- The flaw allows attackers to execute arbitrary code by placing a shared object on target storage due to incorrect access control in NASA cFS v7.0.1's dynamic application start path component.
- Exploitability
- Exploitation requires placing a malicious shared object on the target storage, which could be feasible if proper file system protections are not in place.
- Blast radius
- If exploited, this vulnerability could lead to full compromise of the affected system, potentially allowing unauthorized execution of code with high impact.
- Prioritized remediation
- Update to the latest version of NASA cFS that addresses this issue or apply vendor-provided patches immediately.
rcecode-executionpatch-required
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary code via placing a shared object on target storage.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weaknesses
CWE-284
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.