CVE-2026-60112 is a critical vulnerability in NASA's AIT-GUI before version 2.5.1, allowing unauthenticated network attackers to obtain a valid session and issue arbitrary spacecraft commands via Sessions.create() without credential checks. Rated 9.3 on CVSS v4, it was published on July 29, 2026, and credited to Saidakbarxon Maxsudxonov.