Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.8
CVE-2026-85430: essential-moos up to 10.0.1 allows spoofed UDP messages
CVE-2026-85430 · published 1 month ago
Summary
The essential‑moos software (versions up to 10.0.1) accepts network packets (UDP datagrams) from any source and forwards them with the original sender's identity unchanged. This lets an attacker inject false messages or cause the pShare component to crash. Apply the vendor's update or restrict UDP traffic to trusted sources to mitigate the risk.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| themoos | essential-moos | <= 10.0.1 |
Original advisory text
MOOS essential-moos through 10.0.1 pShare Unauthenticated UDP Datagram Republishing
MOOS essential-moos through 10.0.1 contains an authentication bypass vulnerability in pShare that accepts UDP datagrams from any source and republishes them with the attacker-claimed identity intact. Attackers can send crafted UDP datagrams to pShare input routes to inject messages into the local MOOS community under spoofed identities, or send malformed datagrams to crash the pShare process.
References
- https://github.com/themoos/essential-moos
- https://github.com/themoos/essential-moos/commit/53729b6325a991a8dbd84dcd04e4707...
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85430... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-85430 Vendor Advisory
- https://github.com/themoos/essential-moos/blob/b897ea86dba8b61412dc48ac0cfb5ff34...
- https://github.com/themoos/essential-moos/pull/18
- https://www.vulncheck.com/advisories/moos-essential-moos-through-10.0.1-pshare-u...
Internet-facing
14 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker partial control
Severity
8.8
High
Type
CWE-345Insufficient Verification of Data Authenticity
Timeline
Published3 Sep 2026
Updated7 Oct 2026
First seen3 Sep 2026
Track software like this
Free during beta