CVE-2026-85426
nicheOS Command Injection in MOOS-IvP uMemWatch via Crafted Client Names
MOOS-IvP's uMemWatch application, in all versions through 24.8.1, is vulnerable to OS command injection (CWE-78) because it constructs shell commands from MOOS client names without sanitizing them. An attacker who connects to the MOOS community with a client name containing shell metacharacters can exploit unquoted redirection targets in the resulting system calls to inject additional commands. Successful exploitation grants arbitrary command execution with the privileges of the user running the uMemWatch process, with high impact on the confidentiality, integrity, and availability of that host (CVSS 4.0: 9.3). Affected operators are those running MOOS-IvP-based autonomy stacks, primarily marine robotics research and defense deployments, with uMemWatch active. There is no known public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS currently estimates only a 0.6% probability of exploitation in the next 30 days.
What to do: Upgrade uMemWatch/MOOS-IvP to a release newer than 24.8.1 as soon as a patched version is published by the maintainers. Until then, limit which hosts and users can connect to the MOOS database on the vehicle or host running uMemWatch, and audit whether uMemWatch is enabled and which account it runs as. Because exploitation requires a crafted client name, network segmentation of the MOOS port from untrusted clients is an effective interim mitigation.
| MOOS-IvP uMemWatch | through 24.8.1 (all versions up to and including 24.8.1) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
MOOS-IvP uMemWatch through 24.8.1 constructs shell commands from attacker-chosen MOOS client names without sanitization. Attackers can inject shell metacharacters into client names to execute arbitrary commands as the uMemWatch process user through unquoted redirection targets in system calls.
- Weakness
- CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.