Node Message Source Spoofing Vulnerability in MOOS-IvP by MOOS-IvP
CVE-2026-85429

8.7HIGH

Key Information:

Vendor

Moos-ivp

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-85429?

The MOOS-IvP framework, specifically the uFldNodeComms component, contains a vulnerability where it indiscriminately trusts the source node identity from the message content, bypassing proper validation from the connection source. This flaw allows malicious actors to forge NODE_MESSAGE packets with deceptive source identities, enabling them to impersonate legitimate nodes and send arbitrary variable notifications without undergoing any authentication checks. Such exploitation may jeopardize the reliability and security of network communications.

Affected Version(s)

moos-ivp 0 <= 24.8.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vlatko Kosturjak
.