CVE-2026-85424
MOOS core-moos through 10.4.0 Missing Authentication for MOOSDB Publish, Subscribe and DB_CLEAR
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th
MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect with full publish, subscribe, and database clear privileges. Attackers can bypass the compile-time protocol string check and connect with arbitrary client names to execute privileged operations including DB_CLEAR which resets all variables and clears client mail queues.
| CWE | CWE-306 |
| Vendor | themoos |
| Product | core-moos |
| Published | Sep 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for themoos core-moos
Be the first to know when new critical vulnerabilities affecting themoos core-moos are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
themoos / core-moos
0 โค 10.4.0
References
github.com: https://github.com/themoos/core-moos/pull/84 github.com: https://github.com/themoos/core-moos/commit/5ff5cdec44242156a168cc1a545a6a21357bd3ac github.com: https://github.com/themoos/core-moos github.com: https://github.com/themoos/core-moos/blob/ec9c77c68fcbdef8f5e4c60fe243acd223433f0c/Core/libMOOS/DB/MOOSDB.cpp#L1163 vulncheck.com: https://www.vulncheck.com/advisories/moos-core-moos-through-10.4.0-missing-authentication-for-moosdb-publish-subscribe-and-db-clear
Credits
Vlatko Kosturjak