---
id: CVE-2026-85432
title: >-
  MOOS core-moos through 10.4.0 fails to validate client identity in MOOSDB
  message processing, allowing authenticated attackers to attribute writes to
  other clients by supplying arbitrary source identifiers in serialized messages
summary: >-
  MOOS core-moos through 10.4.0 fails to validate client identity in MOOSDB
  message processing, allowing authenticated attackers to attribute writes to
  other clients by supplying arbitrary source identifiers in serialized
  messages. Attacke…
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L'
cwe:
  - CWE-290
published: '2026-09-03'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:07:17.943'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85432'
references:
  - url: 'https://github.com/themoos/core-moos'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/themoos/core-moos/blob/ec9c77c68fcbdef8f5e4c60fe243acd223433f0c/Core/libMOOS/DB/MOOSDB.cpp#L748
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/themoos/core-moos/commit/26308f0e393f0e80bfa09b275891e776b8dbf522
    label: disclosure@vulncheck.com
  - url: 'https://github.com/themoos/core-moos/pull/76'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/moos-core-moos-through-10.4.0-moosdb-message-source-spoofing-via-wire-identity
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.0051
epssPercentile: 0.40992
ingestedAt: '2026-09-08T20:10:03.161Z'
---

## Overview

MOOS core-moos through 10.4.0 fails to validate client identity in MOOSDB message processing, allowing authenticated attackers to attribute writes to other clients by supplying arbitrary source identifiers in serialized messages. Attackers can forge message origins and cancel third-party subscriptions by exploiting the disconnect between authenticated connection identity and wire-supplied source attribution.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
