SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-85428

CRITICAL · CVSS 9.8 EPSS 0.55% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-03 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The MOOS core-moos versions up to 10.4.0 are vulnerable to an authentication bypass in the optional MOOSDB HTTP server, enabling unauthenticated clients to modify critical variables, including actuator and override commands. This flaw poses a significant risk as it allows attackers to manipulate system behavior without proper authentication, potentially leading to unauthorized control of connected systems. Organizations using MOOS core-moos should prioritize immediate patching or mitigation efforts to safeguard against potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-85428
Severity
CRITICAL
CVSS
9.8
EPSS
0.55%

Original NVD Description

MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that allows unauthenticated clients to write variables. Attackers can send HTTP requests with variable names and values to the MOOSDB HTTP server port to modify MOOS variables including actuator and override commands without authentication.