Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-85433: essential-moos lets unauthorized users reconfigure network routes
CVE-2026-85433 · published 1 month ago
Summary
The essential-moos software (versions up to 10.0.1) does not check who sends certain control messages, so a malicious actor can send crafted commands to open new network listeners or redirect traffic to locations they control. This could let attackers intercept or duplicate data flowing through your system. Apply the latest update from the vendor and restrict network access to trusted devices to mitigate the risk.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| themoos | essential-moos | <= 10.0.1 |
Original advisory text
MOOS essential-moos through 10.0.1 pShare Unauthorized Runtime Route Reconfiguration
MOOS essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing any publisher to reconfigure network routes and listeners at runtime. Attackers can send crafted PSHARE_CMD messages with cmd=output or cmd=input parameters to open new listeners on arbitrary addresses and redirect or duplicate bus traffic to attacker-controlled destinations.
References
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85433... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-85433 Vendor Advisory
- https://github.com/themoos/essential-moos
- https://github.com/themoos/essential-moos/blob/b897ea86dba8b61412dc48ac0cfb5ff34...
- https://github.com/themoos/essential-moos/commit/8e51cedcbd8de9781adec2e9cce354f...
- https://github.com/themoos/essential-moos/pull/20
- https://www.vulncheck.com/advisories/moos-essential-moos-through-10.0.1-pshare-u...
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.3
Critical
Type
CWE-862Missing Authorization
Timeline
Published3 Sep 2026
Updated7 Oct 2026
First seen3 Sep 2026
Track software like this
Free during beta