CVE-2026-85430
Last modified
CVE-2026-85430 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. MOOS essential-moos through 10.0.1 contains an authentication bypass vulnerability in pShare that accepts UDP datagrams from any source and republishes them with the attacker-claimed identity intact. Attackers can send crafted UDP datagrams to pShare input routes to inject messages into the local MOOS community under spoofed identities, or send malformed datagrams to crash the pShare process.. EPSS estimates a 0.95% chance of exploitation in the next 30 days.
Description
MOOS essential-moos through 10.0.1 contains an authentication bypass vulnerability in pShare that accepts UDP datagrams from any source and republishes them with the attacker-claimed identity intact. Attackers can send crafted UDP datagrams to pShare input routes to inject messages into the local MOOS community under spoofed identities, or send malformed datagrams to crash the pShare process.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| themoos | essential-moos | <= 10.0.1 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-85430?
How severe is CVE-2026-85430?
How do I fix CVE-2026-85430?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-85425MOOS-IvP iSay through 24.8.1 contains a remote code executio…9.8
- CVE-2026-85426MOOS-IvP uMemWatch through 24.8.1 constructs shell commands …9.8
- CVE-2026-85427MOOS essential-moos pAntler through 10.0.1 contains a remote…8.1
- CVE-2026-85428MOOS core-moos through 10.4.0 contains an authentication byp…9.8
- CVE-2026-85429MOOS-IvP uFldNodeComms through 24.8.1 trusts the source node…7.5
- CVE-2026-8543Out of bounds read in FileSystem in Google Chrome on Mac pri…5.3
- CVE-2026-85431MOOS essential-moos through version 10.0.1 contains an unaut…7.5
- CVE-2026-85432MOOS core-moos through 10.4.0 fails to validate client ident…8.2
- CVE-2026-85433MOOS essential-moos pShare through 10.0.1 fails to properly …9.8
- CVE-2026-85434MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node…9.1
- CVE-2026-85435MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the…9.1
- CVE-2026-85436MOOS essential-moos through 10.0.1 contains a buffer overflo…7.5
Are you affected by CVE-2026-85430?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
