Junglewise Threat Intelligence

CVE-2026-85429: MOOS-IvP uFldNodeComms message source spoofing

CVE-2026-85429 · Severity: high · CVSS 7.5 · Published 2026-09-03

Vendors: MOOS-IvP.

Executive brief

MOOS-IvP is a set of middleware modules that provide autonomy control and inter-node communication for robotic platforms, including autonomous marine vehicles. A vulnerability in uFldNodeComms allows attackers to spoof the source identity of network messages, enabling an attacker to impersonate authorized nodes and inject arbitrary commands or data into the system, potentially compromising vehicle behavior or mission data integrity.

Technical details

The vulnerability is a lack of source identity validation in uFldNodeComms. The component trusts the source node identity contained within the message body of NODE_MESSAGE packets rather than validating it against the actual network connection source. An attacker with network access can craft malicious NODE_MESSAGE packets with forged source identities and post arbitrary variable notifications without proper authentication, allowing impersonation of legitimate nodes and unauthorized command injection.

Affected products

  • MOOS-IvP uFldNodeComms through 24.8.1

Timeline

  • 2026-09-03: disclosed

References