Node Message Source Spoofing Vulnerability in MOOS-IvP by MOOS-IvP
CVE-2026-85429
8.7HIGH
What is CVE-2026-85429?
The MOOS-IvP framework, specifically the uFldNodeComms component, contains a vulnerability where it indiscriminately trusts the source node identity from the message content, bypassing proper validation from the connection source. This flaw allows malicious actors to forge NODE_MESSAGE packets with deceptive source identities, enabling them to impersonate legitimate nodes and send arbitrary variable notifications without undergoing any authentication checks. Such exploitation may jeopardize the reliability and security of network communications.
Affected Version(s)
moos-ivp 0 <= 24.8.1
