CVE-2026-85425: MOOS-IvP through 24.8.1 iSay Command Injection via SAY_MOOS

Published Sep 3, 2026
·
Updated

MOOS-IvP iSay through 24.8.1 contains a remote code execution vulnerability in the SAYMOOS variable handler that passes unsanitized text to a shell command. Attackers can publish SAYMOOS messages containing backticks or command substitution syntax to execute arbitrary commands as the iSay process user.

Affected Software

1 affected component
MOOS-IvP iSay<=24.8.1

Event History

Sep 3, 2026
CVE Published
via MITRE·10:38 PM
Data Sourced
via MITRE·10:38 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker who can publish messages to the MOOS variable named SAY_MOOS can exploit it remotely. No authentication, user interaction, or special privileges are indicated by the supplied severity vector.

2

What access does successful exploitation provide?

A crafted SAY_MOOS message using backticks or command-substitution syntax can execute arbitrary operating-system commands. Those commands run with the privileges of the iSay process user.

3

Which releases are affected?

MOOS-IvP iSay through version 24.8.1 is affected.

4

What should be prioritized if remediation cannot be applied immediately?

Restrict who can publish to the SAY_MOOS MOOS variable, since publishing attacker-controlled content to that handler is the exploitation prerequisite. Limit the iSay process user's operating-system privileges to reduce the impact of command execution.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203