Vulnerability in MOOS-IvP uFldNodeBroker Allows Unauthorized Shore Route Enrollment
CVE-2026-85435

9.3CRITICAL

Key Information:

Vendor

Moos-ivp

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-85435?

The uFldNodeBroker component of MOOS-IvP, up to version 24.8.1, is susceptible to a vulnerability that allows attackers to enroll unauthorized shore routes on the vehicle bus. This flaw occurs due to the failure to validate the source of TRY_SHORE_HOST messages, enabling to publish malicious messages that can intercept bridged vehicle traffic including sensitive control information and sensor data. Remediation efforts are ongoing, and it is crucial for users to stay informed and apply necessary updates.

Affected Version(s)

moos-ivp 0 <= 24.8.1

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vlatko Kosturjak
.