SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-85424

CRITICAL · CVSS 9.8 EPSS 0.55% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-03 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The MOOS core-moos versions up to 10.4.0 are critically vulnerable due to a lack of authentication in their wire protocol, enabling unauthenticated clients to connect and perform privileged operations such as clearing databases. This vulnerability allows attackers to bypass security checks and execute commands that can disrupt operations and compromise data integrity. Organizations using this software should prioritize immediate remediation to prevent potential exploitation and data loss.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-85424
Severity
CRITICAL
CVSS
9.8
EPSS
0.55%

Original NVD Description

MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect with full publish, subscribe, and database clear privileges. Attackers can bypass the compile-time protocol string check and connect with arbitrary client names to execute privileged operations including DB_CLEAR which resets all variables and clears client mail queues.