CVE-2026-85428
nicheAuthentication Bypass in MOOS core-moos MOOSDB HTTP Server
MOOS core-moos through 10.4.0 contains a missing-authentication flaw (CWE-306) in its optional MOOSDB HTTP server, allowing any unauthenticated client to write MOOS variables. An attacker triggers it simply by sending HTTP requests with chosen variable names and values to the MOOSDB HTTP server port; no credentials or user interaction are required. Because MOOS variables drive robot and vehicle behavior, an attacker can alter actuator commands and override commands, potentially steering or otherwise manipulating a running autonomous system, and the CVSS 4.0 score of 9.3 (critical) reflects high impact to the affected system. Any deployment running MOOSDB with the optional HTTP interface enabled and reachable from an untrusted network is affected; deployments that keep the HTTP server disabled or restrict it to trusted networks are not exposed. There is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at 0.5%, so no exploitation is currently known.
What to do: Upgrade core-moos to a release newer than 10.4.0 once a patched version is available, checking the MOOS project and the VulnCheck advisory for the fixed version. Until then, disable the optional MOOSDB HTTP server if it is not needed, or firewall its port so only trusted hosts can reach it, and verify whether any MOOSDB instances are enabled with HTTP access on routable or vehicle-to-shore networks.
| MOOS project (open source) core-moos (MOOSDB) | through 10.4.0 (all versions up to and including 10.4.0), when the optional MOOSDB HTTP server is enabled |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that allows unauthenticated clients to write variables. Attackers can send HTTP requests with variable names and values to the MOOSDB HTTP server port to modify MOOS variables including actuator and override commands without authentication.
- Weakness
- CWE-306
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.