Remote Code Execution Vulnerability in MOOS's pAntler for Essential-MOOS
CVE-2026-85427

9.2CRITICAL

Key Information:

Vendor

Themoos

Vendor
CVE Published:
3 September 2026

What is CVE-2026-85427?

The essential-moos pAntler component, up to version 10.0.1, is vulnerable to a remote code execution flaw that allows attackers to execute arbitrary commands. By sending a specially crafted MISSION_FILE message to the MOOSDB, unauthenticated users can manipulate pAntler into running malicious code. The vulnerability stems from inadequate validation of mission files, where pAntler parses and executes these files using execvp() without authentication checks. This oversight poses significant security risks, especially when the software is deployed in sensitive environments.

Affected Version(s)

essential-moos 0 <= 10.0.1

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vlatko Kosturjak
.