CVE-2026-85451: MOOS core-moos through 10.4.0 Remote Process Termination via Hard-Coded Multicast Passphrase
MOOS core-moos through 10.4.0 contains a remote process termination vulnerability in the SuicidalSleeper component that uses a hard-coded passphrase for multicast command authorization. Any multicast-reachable peer can enumerate MOOS processes and send termination commands to trigger process shutdown by exploiting the default multicast group and port with the known passphrase.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Deployments of MOOS core-moos through 10.4.0 are exposed when their SuicidalSleeper component is reachable by a peer on the relevant multicast network. The affected authorization uses the default multicast group and port.
What does an attacker need to exploit it?
An attacker does not need credentials or user interaction. They need multicast reachability to the target environment, allowing them to enumerate MOOS processes and send authorized termination commands using the known hard-coded passphrase.
Is the default configuration affected?
Yes. The issue is exploitable through the default multicast group and port because the multicast command authorization passphrase is hard-coded.
What is the operational impact of exploitation?
An attacker can remotely terminate MOOS processes, causing process shutdown and availability disruption. The provided information describes no integrity impact.