Junglewise Threat Intelligence

CVE-2026-85426: MOOS-IvP uMemWatch command injection in client name handling

CVE-2026-85426 · Severity: critical · CVSS 9.8 · Published 2026-09-03

Vendors: MOOS-IvP.

Executive brief

MOOS-IvP uMemWatch is a memory monitoring tool for autonomous marine vehicle software. The vulnerability allows attackers to inject shell commands by providing malicious client names, enabling arbitrary code execution with the privileges of the uMemWatch process. This could compromise robotic systems and the data they collect or control.

Technical details

The vulnerability is a shell command injection flaw in uMemWatch (versions through 24.8.1) where attacker-supplied MOOS client names are used to construct shell commands without proper sanitization. The vulnerable code in MemWatch.cpp passes unquoted client names directly to system calls, allowing injection of shell metacharacters. No authentication is required; an attacker needs only network access to the MOOS middleware to register a malicious client name. Successful exploitation results in arbitrary command execution as the uMemWatch process user. A fix would involve proper quoting or escaping of client names before passing them to shell commands, or preferring direct APIs that do not invoke a shell.

Affected products

  • MOOS-IvP uMemWatch through 24.8.1

Timeline

  • 2026-09-03: disclosed

References