---
id: CVE-2026-85431
title: >-
  MOOS essential-moos through version 10.0.1 contains an unauthenticated UDP
  packet injection vulnerability in pMOOSBridge when configured with UDPListen
summary: >-
  MOOS essential-moos through version 10.0.1 contains an unauthenticated UDP
  packet injection vulnerability in pMOOSBridge when configured with UDPListen.
  Attackers can send crafted UDP packets to the configured port to inject
  arbitrary va…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-345
published: '2026-09-03'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:07:17.943'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85431'
references:
  - url: 'https://github.com/themoos/essential-moos'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/themoos/essential-moos/blob/b897ea86dba8b61412dc48ac0cfb5ff34cdaf5f6/Essentials/pMOOSBridge/MOOSUDPLink.cpp#L21
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/themoos/essential-moos/commit/d8441eac57d04ee89e7b82723480d10a558b45d6
    label: disclosure@vulncheck.com
  - url: 'https://github.com/themoos/essential-moos/pull/19'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/moos-essential-moos-through-10.0.1-pmoosbridge-unauthenticated-udp-packet-injection
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.02845
epssPercentile: 0.86125
ingestedAt: '2026-09-08T20:10:03.161Z'
---

## Overview

MOOS essential-moos through version 10.0.1 contains an unauthenticated UDP packet injection vulnerability in pMOOSBridge when configured with UDPListen. Attackers can send crafted UDP packets to the configured port to inject arbitrary variables into the local MOOS community with spoofed source and community identifiers.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
