---
id: CVE-2026-85433
title: >-
  MOOS essential-moos pShare through 10.0.1 fails to properly authorize
  PSHARE_CMD messages, allowing any publisher to reconfigure network routes and
  listeners at runtime
summary: >-
  MOOS essential-moos pShare through 10.0.1 fails to properly authorize
  PSHARE_CMD messages, allowing any publisher to reconfigure network routes and
  listeners at runtime. Attackers can send crafted PSHARE_CMD messages with
  cmd=output or c…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-862
vendor: themoos
product: essential-moos
affected:
  - essential-moos <= 10.0.1
published: '2026-09-03'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T14:17:13.830'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85433'
references:
  - url: 'https://github.com/themoos/essential-moos'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/themoos/essential-moos/blob/b897ea86dba8b61412dc48ac0cfb5ff34cdaf5f6/Essentials/pShare/Share.cpp#L813
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/themoos/essential-moos/commit/8e51cedcbd8de9781adec2e9cce354f51750a547
    label: disclosure@vulncheck.com
  - url: 'https://github.com/themoos/essential-moos/pull/20'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/moos-essential-moos-through-10.0.1-pshare-unauthorized-runtime-route-reconfiguration
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-14T13:17:55.341619Z'
epss: 0.00621
epssPercentile: 0.47642
ingestedAt: '2026-09-08T20:10:03.161Z'
---

## Overview

MOOS essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing any publisher to reconfigure network routes and listeners at runtime. Attackers can send crafted PSHARE_CMD messages with cmd=output or cmd=input parameters to open new listeners on arbitrary addresses and redirect or duplicate bus traffic to attacker-controlled destinations.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
