MOOSDB Message Source Spoofing in MOOS Core by The MOOS Team
CVE-2026-85432

8.8HIGH

Key Information:

Vendor

Themoos

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-85432?

MOOS core-moos versions through 10.4.0 contain a vulnerability in the processing of messages within MOOSDB, where client identity validation is inadequate. This flaw permits authenticated users to manipulate message attribution by injecting arbitrary source identifiers within serialized messages. As a result, attackers can falsely represent the origins of messages and potentially disrupt or cancel third-party subscriptions, exploiting the disconnect between the authenticated connection identity and the source attribution derived from the wire.

Affected Version(s)

core-moos 0 <= 10.4.0

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vlatko Kosturjak
.