Remote Process Termination Vulnerability in MOOS Core-MOOS by MOOS
CVE-2026-85451

7.1HIGH

Key Information:

Vendor

Themoos

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-85451?

The core-moos product by MOOS, up to version 10.4.0, contains a vulnerability in its SuicidalSleeper component that allows remote process termination. This issue is caused by a hard-coded passphrase utilized for multicast command authorization. An attacker can exploit this vulnerability by targeting any multicast-reachable peer, enabling them to enumerate processes within the MOOS environment. Once identified, the attacker can send unauthorized termination commands over the default multicast group and port, resulting in unintended shutdowns of MOOS processes.

Affected Version(s)

core-moos 0 <= 10.4.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vlatko Kosturjak
.