CRITICAL 9.3 NVD

CVE-2026-85428

MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that allows unauthenticated clients to write va

MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that allows unauthenticated clients to write variables. Attackers can send HTTP requests with variable names and values to the MOOSDB HTTP server port to modify MOOS variables including actuator and override commands without authentication.

References

Published: 2026-09-03 · Source: NVD · Feed updated: 2026-09-04
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-09-03 via NVD.

Risk Timeline

CVE Disclosed2026-09-03 · 0 days ago

Remediation Resources

vulnfeed aggregates 7585 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.