CVE-2026-79954
Last modified
CVE-2026-79954 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiver selects the Security Association used for SDLS processing solely from the SPI field inside the incoming frame, but it does not verify that the selected SA is authorized for the frame's GVCID..
Description
NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiver selects the Security Association used for SDLS processing solely from the SPI field inside the incoming frame, but it does not verify that the selected SA is authorized for the frame's GVCID.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| NASA | CryptoLib | 1.5.0 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-79954?
How severe is CVE-2026-79954?
How do I fix CVE-2026-79954?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-79945Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell…5.5
- CVE-2026-79946Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell…5.3
- CVE-2026-79947Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell…5.5
- CVE-2026-7995Out of bounds read in AdFilter in Google Chrome prior to 148…8.8
- CVE-2026-79950Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell…7.5
- CVE-2026-79952Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell…5.3
- CVE-2026-79959The Botslab G980H dash camera firmware contains a hard-coded…6.8
- CVE-2026-7996Insufficient validation of untrusted input in SSL in Google …4.2
- CVE-2026-79961Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell…5.3
- CVE-2026-79962Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell…5.9
- CVE-2026-79963Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell…7.4
- CVE-2026-79964Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell…5.3
Are you affected by CVE-2026-79954?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
