Buffer Overflow Vulnerability in MOOS UI-MOOS by The MOOS
CVE-2026-85452

8.7HIGH

Key Information:

Vendor

Themoos

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-85452?

The MOOS UI-MOOS product contains a buffer overflow vulnerability in ScopeTabPane.cpp and ScopeGrid.cpp modules. The vulnerability arises when client and variable names are formatted into fixed 1024-byte buffers using the 'sprintf' function without proper length validation. This allows attackers to supply excessively long MOOS identifiers that can overflow the buffers. Exploiting this vulnerability occurs when an operator selects process list entries or interacts with variables, which could lead to arbitrary code execution.

Affected Version(s)

ui-moos 0 <= 50b9c6c

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vlatko Kosturjak
.