ZeroHour

CVE-2026-85426

niche

OS Command Injection in MOOS-IvP uMemWatch via Crafted Client Names

CVSS 4.0
9.3 critical
EPSS
<1%p47
Published
()
Modified
AI analysis

MOOS-IvP's uMemWatch application, in all versions through 24.8.1, is vulnerable to OS command injection (CWE-78) because it constructs shell commands from MOOS client names without sanitizing them. An attacker who connects to the MOOS community with a client name containing shell metacharacters can exploit unquoted redirection targets in the resulting system calls to inject additional commands. Successful exploitation grants arbitrary command execution with the privileges of the user running the uMemWatch process, with high impact on the confidentiality, integrity, and availability of that host (CVSS 4.0: 9.3). Affected operators are those running MOOS-IvP-based autonomy stacks, primarily marine robotics research and defense deployments, with uMemWatch active. There is no known public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS currently estimates only a 0.6% probability of exploitation in the next 30 days.

What to do: Upgrade uMemWatch/MOOS-IvP to a release newer than 24.8.1 as soon as a patched version is published by the maintainers. Until then, limit which hosts and users can connect to the MOOS database on the vehicle or host running uMemWatch, and audit whether uMemWatch is enabled and which account it runs as. Because exploitation requires a crafted client name, network segmentation of the MOOS port from untrusted clients is an effective interim mitigation.

Affected
MOOS-IvP uMemWatchthrough 24.8.1 (all versions up to and including 24.8.1)
Estimated exposure
nichelikely hundreds to low thousands of deployments (no public install counts) — MOOS-IvP is a specialized open-source autonomy middleware used mainly in academic, research, and defense marine robotics (unmanned surface/underwater vehicles), and uMemWatch is a single auxiliary app within that stack, so the plausible…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

MOOS-IvP uMemWatch through 24.8.1 constructs shell commands from attacker-chosen MOOS client names without sanitization. Attackers can inject shell metacharacters into client names to execute arbitrary commands as the uMemWatch process user through unquoted redirection targets in system calls.

Weakness
CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.