CVE-2026-85430: MOOS essential-moos through 10.0.1 pShare Unauthenticated UDP Datagram Republishing
MOOS essential-moos through 10.0.1 contains an authentication bypass vulnerability in pShare that accepts UDP datagrams from any source and republishes them with the attacker-claimed identity intact. Attackers can send crafted UDP datagrams to pShare input routes to inject messages into the local MOOS community under spoofed identities, or send malformed datagrams to crash the pShare process.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Deployments of essential-moos through version 10.0.1 that run pShare and accept UDP datagrams on pShare input routes are exposed. The vulnerable behavior accepts datagrams from any source.
What does an attacker need to exploit it?
An attacker needs only the ability to send UDP datagrams to a pShare input route. No authentication, privileges, or user interaction are required.
What can successful exploitation do?
An attacker can inject messages into the local MOOS community while preserving an attacker-claimed, spoofed identity. Malformed UDP datagrams can also crash the pShare process, causing a denial of service.