LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-85428

Published
CVSS9.8
Severitycritical
WeaknessCWE-306
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that allows unauthenticated clients to write variables. Attackers can send HTTP requests with variable names and values to the MOOSDB HTTP server port to modify MOOS variables including actuator and override commands without authentication.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-85428

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-85428.