Unauthenticated UDP Packet Injection in MOOS Essential-MOOS by TheMOOS
CVE-2026-85431

8.7HIGH

Key Information:

Vendor

Themoos

Vendor
CVE Published:
3 September 2026

What is CVE-2026-85431?

MOOS Essential-MOOS up to version 10.0.1 contains a vulnerability allowing attackers to exploit unauthenticated UDP packet injection through the pMOOSBridge component when configured with UDPListen. This flaw permits the injection of arbitrary variables into the local MOOS community by sending crafted UDP packets, which can have spoofed source and community identifiers, potentially compromising system integrity and confidentiality.

Affected Version(s)

essential-moos 0 <= 10.0.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vlatko Kosturjak
.