MOOSDB Message Source Spoofing in MOOS Core by The MOOS Team
CVE-2026-85432
8.8HIGH
What is CVE-2026-85432?
MOOS core-moos versions through 10.4.0 contain a vulnerability in the processing of messages within MOOSDB, where client identity validation is inadequate. This flaw permits authenticated users to manipulate message attribution by injecting arbitrary source identifiers within serialized messages. As a result, attackers can falsely represent the origins of messages and potentially disrupt or cancel third-party subscriptions, exploiting the disconnect between the authenticated connection identity and the source attribution derived from the wire.
Affected Version(s)
core-moos 0 <= 10.4.0
