Remote Code Execution Vulnerability in MOOS's pAntler for Essential-MOOS
CVE-2026-85427
9.2CRITICAL
What is CVE-2026-85427?
The essential-moos pAntler component, up to version 10.0.1, is vulnerable to a remote code execution flaw that allows attackers to execute arbitrary commands. By sending a specially crafted MISSION_FILE message to the MOOSDB, unauthenticated users can manipulate pAntler into running malicious code. The vulnerability stems from inadequate validation of mission files, where pAntler parses and executes these files using execvp() without authentication checks. This oversight poses significant security risks, especially when the software is deployed in sensitive environments.
Affected Version(s)
essential-moos 0 <= 10.0.1
