---
id: CVE-2026-85430
title: >-
  MOOS essential-moos through 10.0.1 contains an authentication bypass
  vulnerability in pShare that accepts UDP datagrams from any source and
  republishes them with the attacker-claimed identity intact
summary: >-
  MOOS essential-moos through 10.0.1 contains an authentication bypass
  vulnerability in pShare that accepts UDP datagrams from any source and
  republishes them with the attacker-claimed identity intact. Attackers can send
  crafted UDP datagr…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'
cwe:
  - CWE-345
published: '2026-09-03'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:07:17.943'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85430'
references:
  - url: 'https://github.com/themoos/essential-moos'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/themoos/essential-moos/blob/b897ea86dba8b61412dc48ac0cfb5ff34cdaf5f6/Essentials/pShare/Listener.cpp#L132
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/themoos/essential-moos/commit/53729b6325a991a8dbd84dcd04e4707f3e592fd6
    label: disclosure@vulncheck.com
  - url: 'https://github.com/themoos/essential-moos/pull/18'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/moos-essential-moos-through-10.0.1-pshare-unauthenticated-udp-datagram-republishing
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.0131
epssPercentile: 0.69434
ingestedAt: '2026-09-08T20:10:03.161Z'
---

## Overview

MOOS essential-moos through 10.0.1 contains an authentication bypass vulnerability in pShare that accepts UDP datagrams from any source and republishes them with the attacker-claimed identity intact. Attackers can send crafted UDP datagrams to pShare input routes to inject messages into the local MOOS community under spoofed identities, or send malformed datagrams to crash the pShare process.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
