CVE-2026-85451: MOOS core-moos through 10.4.0 Remote Process Termination via Hard-Coded Multicast Passphrase

Published Sep 3, 2026
·
Updated

MOOS core-moos through 10.4.0 contains a remote process termination vulnerability in the SuicidalSleeper component that uses a hard-coded passphrase for multicast command authorization. Any multicast-reachable peer can enumerate MOOS processes and send termination commands to trigger process shutdown by exploiting the default multicast group and port with the known passphrase.

Affected Software

1 affected component
core-moos<=10.4.0

Event History

Sep 3, 2026
CVE Published
via MITRE·10:38 PM
Data Sourced
via MITRE·10:38 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Deployments of MOOS core-moos through 10.4.0 are exposed when their SuicidalSleeper component is reachable by a peer on the relevant multicast network. The affected authorization uses the default multicast group and port.

2

What does an attacker need to exploit it?

An attacker does not need credentials or user interaction. They need multicast reachability to the target environment, allowing them to enumerate MOOS processes and send authorized termination commands using the known hard-coded passphrase.

3

Is the default configuration affected?

Yes. The issue is exploitable through the default multicast group and port because the multicast command authorization passphrase is hard-coded.

4

What is the operational impact of exploitation?

An attacker can remotely terminate MOOS processes, causing process shutdown and availability disruption. The provided information describes no integrity impact.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203