CVE-2026-85433
nicheMissing Authorization in MOOS essential-moos pShare Allows Bus Traffic Redirection
MOOS essential-moos pShare through version 10.0.1 fails to properly authorize PSHARE_CMD messages (CWE-862), meaning any publisher connected to the MOOS bus can reconfigure network routes and listeners at runtime without restriction. An attacker sends crafted PSHARE_CMD messages with cmd=output or cmd=input parameters to open new listeners on arbitrary addresses and redirect or duplicate bus traffic to attacker-controlled destinations. Successful exploitation gives the attacker high confidentiality, integrity, and availability impact on the affected bus, since they can intercept, divert, or duplicate inter-process communications. Any deployment running pShare in essential-moos version 10.0.1 or earlier is affected, primarily robotics and autonomy research/operational systems that use this middleware. No public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at just 0.3%, so no exploitation is currently known.
What to do: Upgrade essential-moos/pShare to a release newer than 10.0.1 as soon as a patched version is published (no fixed version is specified in the advisory data). Until then, restrict network access to MOOS bus ports to trusted hosts, limit which nodes may send PSHARE_CMD messages, and check running pShare instances for unexpected listeners or duplicated/redirected traffic on non-standard addresses.
| MOOS essential-moos (pShare) | through 10.0.1 (all versions up to and including 10.0.1) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
MOOS essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing any publisher to reconfigure network routes and listeners at runtime. Attackers can send crafted PSHARE_CMD messages with cmd=output or cmd=input parameters to open new listeners on arbitrary addresses and redirect or duplicate bus traffic to attacker-controlled destinations.
- Weakness
- CWE-862
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.