CVE-2026-85433

Summary

MOOS essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing any publisher to reconfigure network routes and listeners at runtime. Attackers can send crafted PSHARE_CMD messages with cmd=output or cmd=input parameters to open new listeners on arbitrary addresses and redirect or duplicate bus traffic to attacker-controlled destinations.

Affected Software

VendorProductVersion RangeStatus
themoosessential-moos0 <= 10.0.1affected

Weaknesses

  • CWE-862: Missing Authorization

References