Executive brief
MOOS is a lightweight middleware system used in robotics and autonomous systems to manage communication between software components. The optional MOOSDB HTTP server, when enabled, contains a critical flaw that allows unauthenticated attackers to modify system variables (including commands that control actuators and safety overrides) by sending simple HTTP requests. This could enable attackers to take control of robotic systems or autonomous platforms without any credentials.
Technical details
The vulnerability is an authentication bypass in the MOOSDB HTTP server component (HTTPConnection.cpp) that fails to properly validate requests before allowing variable writes. Unauthenticated clients can send HTTP requests with variable names and values directly to the MOOSDB HTTP server port, bypassing all access controls. The vulnerability affects core-moos through version 10.4.0 and is reachable remotely over the network if the optional HTTP server is enabled. An attacker can modify any MOOS variable including actuator commands and safety override flags, potentially causing loss of control or unintended system behavior. A patch addressing the authentication bypass is expected to be available in a future release.
Affected products
- MOOS core-moos through 10.4.0
Timeline
- 2026-09-03: disclosed