CVE-2026-72577 addresses critical weaknesses in NASA fprime-gds, the ground data system used with NASA JPL's F Prime flight software framework.
The Flask-based interface does not enforce authentication on critical endpoints. Combined with related file-handling and session weaknesses, an unauthenticated remote attacker can compromise the ground-station host and, where connected, inject unauthorized commands toward spacecraft or embedded flight targets under GDS control.
This class of issue is especially severe because ground systems are often trusted uplink paths. Operators should restrict network exposure immediately, monitor for patched releases, and validate deployments against the official CVE and advisory references.