Bridge Route Injection Vulnerability in MOOS-IvP's uFldShoreBroker
CVE-2026-85434
9.3CRITICAL
What is CVE-2026-85434?
The uFldShoreBroker component of MOOS-IvP versions up to 24.8.1 is susceptible to a significant vulnerability that allows attackers to exploit the system by sending crafted NODE_BROKER_PING messages. This occurs due to a failure to properly verify the authenticity of node pings before establishing outbound bridge routes. As a result, attackers can redirect bridged variables to addresses under their control, potentially compromising the integrity and confidentiality of the affected systems.
Affected Version(s)
moos-ivp 0 <= 24.8.1
