CVE-2026-85428
MOOS core-moos through 10.4.0 MOOSDB HTTP Server Unauthenticated Variable Write
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th
MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that allows unauthenticated clients to write variables. Attackers can send HTTP requests with variable names and values to the MOOSDB HTTP server port to modify MOOS variables including actuator and override commands without authentication.
| CWE | CWE-306 |
| Vendor | themoos |
| Product | core-moos |
| Published | Sep 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for themoos core-moos
Be the first to know when new critical vulnerabilities affecting themoos core-moos are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
themoos / core-moos
0 โค 10.4.0
References
github.com: https://github.com/themoos/core-moos/pull/77 github.com: https://github.com/themoos/core-moos/commit/7e3aecdbf5fe47980ea9399340c77940991a6fa5 github.com: https://github.com/themoos/core-moos github.com: https://github.com/themoos/core-moos/blob/ec9c77c68fcbdef8f5e4c60fe243acd223433f0c/Core/libMOOS/DB/HTTPConnection.cpp#L196 vulncheck.com: https://www.vulncheck.com/advisories/moos-core-moos-through-10.4.0-moosdb-http-server-unauthenticated-variable-write
Credits
Vlatko Kosturjak