Junglewise Threat Intelligence

CVE-2026-85440: MOOS core-moos pre-authentication heap overflow in MOOSCommPkt

CVE-2026-85440 · Severity: critical · CVSS 9.8 · Published 2026-09-03

Technologies: MOOS Core-Moos. Vendors: MOOS.

Executive brief

MOOS is a lightweight middleware platform used in robotics and autonomous systems for inter-process communication. This vulnerability allows remote attackers to exploit the packet handling mechanism before authentication, potentially leading to remote code execution and full system compromise on affected MOOS deployments.

Technical details

The vulnerability is a pre-authentication heap buffer overflow in the MOOSCommPkt packet handler, specifically in the InflateTo() and recv() functions. An attacker can craft a malicious packet with a negative length value that bypasses signed integer checks and causes a four-byte heap buffer to overflow during the HandShake phase before any authentication occurs. This occurs because the negative size declaration is not properly validated before being used in memory operations. The overflow permits arbitrary data write and can lead to remote code execution. The vulnerability affects core-moos through version 10.4.0, and a patch is required.

Affected products

  • MOOS core-moos through 10.4.0

Timeline

  • 2026-09-03: disclosed

References

Related threats