CVE-2026-85434: MOOS-IvP through 24.8.1 uFldShoreBroker Bridge Route Injection via Unverified Node Ping
MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge routes. Attackers can publish NODEBROKERPING messages with crafted HostRecord data to redirect bridged variables to attacker-controlled addresses.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Deployments using the MOOS-IvP uFldShoreBroker Bridge through version 24.8.1 are exposed if they process NODE_BROKER_PING messages that an attacker can publish.
What does an attacker need to exploit it?
An attacker needs the ability to publish a NODE_BROKER_PING message with crafted HostRecord data. No privileges or user interaction are required according to the supplied vector.
What is the impact of a successful attack?
The attacker can cause outbound bridge routes to be created for attacker-controlled addresses, redirecting bridged variables. The supplied severity vector indicates high confidentiality and integrity impact, with no availability impact.
How can I determine whether my deployment is affected?
Check whether the deployment uses uFldShoreBroker Bridge in MOOS-IvP version 24.8.1 or earlier and accepts NODE_BROKER_PING messages without authenticating them before creating outbound bridge routes.