---
id: CVE-2026-85428
title: >-
  MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability
  in the optional MOOSDB HTTP server that allows unauthenticated clients to
  write variables
summary: >-
  MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability
  in the optional MOOSDB HTTP server that allows unauthenticated clients to
  write variables. Attackers can send HTTP requests with variable names and
  values to t…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-306
vendor: themoos
product: core-moos
affected:
  - core-moos <= 10.4.0
published: '2026-09-03'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T14:17:13.663'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85428'
references:
  - url: 'https://github.com/themoos/core-moos'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/themoos/core-moos/blob/ec9c77c68fcbdef8f5e4c60fe243acd223433f0c/Core/libMOOS/DB/HTTPConnection.cpp#L196
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/themoos/core-moos/commit/7e3aecdbf5fe47980ea9399340c77940991a6fa5
    label: disclosure@vulncheck.com
  - url: 'https://github.com/themoos/core-moos/pull/77'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/moos-core-moos-through-10.4.0-moosdb-http-server-unauthenticated-variable-write
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-14T13:07:42.580945Z'
epss: 0.00818
epssPercentile: 0.5535
ingestedAt: '2026-09-08T20:10:03.161Z'
---

## Overview

MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that allows unauthenticated clients to write variables. Attackers can send HTTP requests with variable names and values to the MOOSDB HTTP server port to modify MOOS variables including actuator and override commands without authentication.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
