CVE-2026-85439: MOOS-IvP through 24.8.1 alogsplit Command Injection via Input Pathname

Published Sep 3, 2026
·
Updated

MOOS-IvP through 24.8.1 contains a remote code execution vulnerability in alogsplit's SplitHandler::handlePreCheckSplitDir() function that fails to sanitize shell metacharacters in log file pathnames. Attackers can embed shell syntax in log file names or the --dir parameter to execute arbitrary commands with the privileges of the operator running alogsplit.

Affected Software

1 affected component
MOOS MOOS-IvP<=24.8.1

Event History

Sep 3, 2026
CVE Published
via MITRE·10:38 PM
Data Sourced
via MITRE·10:38 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What access or interaction is required to exploit this issue?

An attacker must be able to cause alogsplit to process a log-file pathname containing shell syntax, or influence the value supplied through its --dir parameter. Exploitation occurs when an operator runs alogsplit on that input.

2

Which accounts and systems are at risk?

Systems are at risk where an operator runs alogsplit against attacker-controlled or untrusted log filenames or attacker-influenced output-directory values. Commands execute with the privileges of the operator who runs alogsplit.

3

What can be done while a fix is being deployed?

Do not run alogsplit on untrusted log files or with untrusted --dir values. Restrict log filenames and directory arguments to trusted paths that do not contain shell metacharacters, and run the tool with the least privileges practical.

4

How can I determine whether an installation is affected?

MOOS-IvP versions through 24.8.1 are affected. Review alogsplit usage for processing of externally supplied log paths or --dir arguments, especially where filenames may contain shell metacharacters.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203