ZeroHour

CVE-2026-85428

niche

Authentication Bypass in MOOS core-moos MOOSDB HTTP Server

CVSS 4.0
9.3 critical
EPSS
<1%p44
Published
()
Modified
AI analysis

MOOS core-moos through 10.4.0 contains a missing-authentication flaw (CWE-306) in its optional MOOSDB HTTP server, allowing any unauthenticated client to write MOOS variables. An attacker triggers it simply by sending HTTP requests with chosen variable names and values to the MOOSDB HTTP server port; no credentials or user interaction are required. Because MOOS variables drive robot and vehicle behavior, an attacker can alter actuator commands and override commands, potentially steering or otherwise manipulating a running autonomous system, and the CVSS 4.0 score of 9.3 (critical) reflects high impact to the affected system. Any deployment running MOOSDB with the optional HTTP interface enabled and reachable from an untrusted network is affected; deployments that keep the HTTP server disabled or restrict it to trusted networks are not exposed. There is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at 0.5%, so no exploitation is currently known.

What to do: Upgrade core-moos to a release newer than 10.4.0 once a patched version is available, checking the MOOS project and the VulnCheck advisory for the fixed version. Until then, disable the optional MOOSDB HTTP server if it is not needed, or firewall its port so only trusted hosts can reach it, and verify whether any MOOSDB instances are enabled with HTTP access on routable or vehicle-to-shore networks.

Affected
MOOS project (open source) core-moos (MOOSDB)through 10.4.0 (all versions up to and including 10.4.0), when the optional MOOSDB HTTP server is enabled
Estimated exposure
nichelikely hundreds to low thousands of robotics/research deployments worldwide; internet-exposed instances unknown — MOOS is a niche open-source robotics middleware used mainly in academic and marine-autonomy research, the vulnerable HTTP interface is an optional component, and MOOSDB typically runs on internal or on-board vehicle networks rather than…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that allows unauthenticated clients to write variables. Attackers can send HTTP requests with variable names and values to the MOOSDB HTTP server port to modify MOOS variables including actuator and override commands without authentication.

Weakness
CWE-306
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.