CVE-2026-85430
nicheAuthentication Bypass in MOOS essential-moos pShare Enables UDP Message Spoofing
MOOS essential-moos through 10.0.1 contains an authentication bypass (CWE-345) in its pShare component, which accepts UDP datagrams on inter-community routes without verifying the sender's authenticity and republishes them with the attacker-claimed identity intact. An attacker who can reach a pShare input route over the network can inject crafted datagrams into the local MOOS community under spoofed process identities, or send malformed datagrams to crash the pShare process. The practical impact is falsified or corrupted inter-process messaging and denial of service, consistent with the 8.8 (high) CVSS 4.0 score reflecting high integrity and availability impacts with no direct confidentiality loss. Affected users are operators of MOOS-based autonomy and robotics systems, notably research and marine-autonomy deployments that use pShare to bridge separate MOOS communities. No exploitation in the wild, public proof-of-concept, or KEV listing is known; EPSS currently estimates a 1.0% probability of exploitation within 30 days.
What to do: Apply network filtering (firewall rules or access control lists) to pShare's UDP input routes so only trusted peer MOOS communities can reach them, and confirm pShare is not exposed to untrusted or internet-facing networks. Monitor the MOOS project for a fixed release beyond 10.0.1 and upgrade when one becomes available; no public PoC or in-the-wild exploitation is currently known.
| MOOS Project essential-moos | all versions through and including 10.0.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
MOOS essential-moos through 10.0.1 contains an authentication bypass vulnerability in pShare that accepts UDP datagrams from any source and republishes them with the attacker-claimed identity intact. Attackers can send crafted UDP datagrams to pShare input routes to inject messages into the local MOOS community under spoofed identities, or send malformed datagrams to crash the pShare process.
- Weakness
- CWE-345
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.