ZeroHour

CVE-2026-85430

niche

Authentication Bypass in MOOS essential-moos pShare Enables UDP Message Spoofing

CVSS 4.0
8.8 high
EPSS
<1%p59
Published
()
Modified
AI analysis

MOOS essential-moos through 10.0.1 contains an authentication bypass (CWE-345) in its pShare component, which accepts UDP datagrams on inter-community routes without verifying the sender's authenticity and republishes them with the attacker-claimed identity intact. An attacker who can reach a pShare input route over the network can inject crafted datagrams into the local MOOS community under spoofed process identities, or send malformed datagrams to crash the pShare process. The practical impact is falsified or corrupted inter-process messaging and denial of service, consistent with the 8.8 (high) CVSS 4.0 score reflecting high integrity and availability impacts with no direct confidentiality loss. Affected users are operators of MOOS-based autonomy and robotics systems, notably research and marine-autonomy deployments that use pShare to bridge separate MOOS communities. No exploitation in the wild, public proof-of-concept, or KEV listing is known; EPSS currently estimates a 1.0% probability of exploitation within 30 days.

What to do: Apply network filtering (firewall rules or access control lists) to pShare's UDP input routes so only trusted peer MOOS communities can reach them, and confirm pShare is not exposed to untrusted or internet-facing networks. Monitor the MOOS project for a fixed release beyond 10.0.1 and upgrade when one becomes available; no public PoC or in-the-wild exploitation is currently known.

Affected
MOOS Project essential-moosall versions through and including 10.0.1
Estimated exposure
nichelikely hundreds to low thousands of deployments; exact count unknown — essential-moos is a niche open-source robotics middleware used mainly in academic and marine-autonomy programs, and with no public active-install counts or internet-exposure scan data, this estimate rests on its specialized deployment…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

MOOS essential-moos through 10.0.1 contains an authentication bypass vulnerability in pShare that accepts UDP datagrams from any source and republishes them with the attacker-claimed identity intact. Attackers can send crafted UDP datagrams to pShare input routes to inject messages into the local MOOS community under spoofed identities, or send malformed datagrams to crash the pShare process.

Weakness
CWE-345
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.