Junglewise Threat Intelligence

CVE-2026-85430: MOOS pShare authentication bypass in UDP listener

CVE-2026-85430 · Severity: critical · CVSS 9.1 · Published 2026-09-03

Technologies: MOOS Essential-Moos. Vendors: MOOS.

Executive brief

MOOS pShare is a distributed messaging relay used in robotics and autonomous systems to share data across multiple MOOS communities over the network. This vulnerability allows attackers to send spoofed UDP messages that are republished into a MOOS community under a false sender identity, or to crash the pShare process entirely. An attacker on the network can inject malicious commands, sensor readings, or navigation data, disrupting operations or enabling further compromise of autonomous systems.

Technical details

The vulnerability is an authentication bypass in pShare's UDP listener (Listener.cpp). The listener accepts and republishes UDP datagrams from any source without validating the sender's identity or legitimacy, preserving the attacker-claimed identity in the message. The root cause is missing source authentication and validation on incoming UDP datagrams. An attacker with network access to the pShare listening port can send crafted datagrams to inject spoofed messages into the MOOS community, or send malformed packets to trigger a process crash. No patch information is currently available in the advisory. The attack requires network reachability to the pShare UDP listener port; no authentication is required.

Affected products

  • MOOS essential-moos through 10.0.1

Timeline

  • 2026-09-03: disclosed

References

Related threats