Remote Process Termination Vulnerability in MOOS Core-MOOS by MOOS
CVE-2026-85451
7.1HIGH
What is CVE-2026-85451?
The core-moos product by MOOS, up to version 10.4.0, contains a vulnerability in its SuicidalSleeper component that allows remote process termination. This issue is caused by a hard-coded passphrase utilized for multicast command authorization. An attacker can exploit this vulnerability by targeting any multicast-reachable peer, enabling them to enumerate processes within the MOOS environment. Once identified, the attacker can send unauthorized termination commands over the default multicast group and port, resulting in unintended shutdowns of MOOS processes.
Affected Version(s)
core-moos 0 <= 10.4.0
