Junglewise Threat Intelligence

CVE-2026-72579: NASA HyperCP OS command injection via DNS spoofing

CVE-2026-72579 · Severity: high · CVSS 7.5 · Published 2026-08-10

Vendors: Nasa.

Executive brief

NASA HyperCP is a scientific data processing tool used by oceanographic researchers. An attacker on the same network who can intercept or spoof DNS responses can trick the software into executing arbitrary system commands on a researcher's workstation, potentially compromising sensitive data or the research environment.

Technical details

The vulnerability is an OS command injection flaw in NASA HyperCP's main branch, triggered when the application processes data from oceandata.sci.gsfc.nasa.gov. An attacker with network-adjacent access (capable of ARP spoofing, DNS hijacking, or man-in-the-middle interception) can spoof responses from the remote server. The application does not properly sanitize or validate the server responses before passing them to system command execution, allowing arbitrary command injection. This requires network proximity and the ability to intercept or spoof DNS/network traffic, but does not require user authentication or interaction. Patches or fixes may be available in the repository; consult the NASA HyperCP project for remediation.

Affected products

  • NASA HyperCP main branch

Timeline

  • 2026-08-10: disclosed

References