MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that allows unauthenticated clients to write variables. Attackers can send HTTP requests with variable names and values to the MOOSDB HTTP server port to modify MOOS variables including actuator and override commands without authentication.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-03 23:17
Updated : 2026-09-14 14:17
NVD link : CVE-2026-85428
Mitre link : CVE-2026-85428
CVE.ORG link : CVE-2026-85428
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function
