← Back to search

CVE-2026-67979

9.1 CRITICALpublic exploit available

Published 2026-08-04 · Updated 2026-08-05

AI risk analysis

Summary
The flaw allows attackers to execute arbitrary code by placing a shared object on target storage due to incorrect access control in NASA cFS v7.0.1's dynamic application start path component.
Exploitability
Exploitation requires placing a malicious shared object on the target storage, which could be feasible if proper file system protections are not in place.
Blast radius
If exploited, this vulnerability could lead to full compromise of the affected system, potentially allowing unauthorized execution of code with high impact.
Prioritized remediation
Update to the latest version of NASA cFS that addresses this issue or apply vendor-provided patches immediately.
rcecode-executionpatch-required

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary code via placing a shared object on target storage.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Weaknesses

CWE-284

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.