CVE-2026-85433
9.8themoos · essential-moos
The pShare component in essential-moos fails to authorize PSHARE_CMD messages, allowing unauthenticated attackers to reconfigure network routes and listeners at runtime.
Executive summary
A critical vulnerability in the essential-moos pShare component allows unauthenticated attackers to manipulate network traffic flows and intercept sensitive data.
Vulnerability
This is a missing authorization vulnerability (CWE-862) occurring within the pShare component. An unauthenticated attacker can send crafted PSHARE_CMD messages to the application, enabling them to reconfigure network listeners and redirect or duplicate bus traffic to external, attacker-controlled destinations.
Business impact
The ability for an unauthorized party to redirect or mirror internal network traffic represents a severe risk to data confidentiality and operational integrity. Successful exploitation could lead to the interception of sensitive system communications, unauthorized data exfiltration, and potential compromise of the entire MOOS environment. With a CVSS score of 9.8, this flaw is categorized as critical, as it requires no authentication and allows for full control over message routing.
Remediation
Immediate Action: Update essential-moos to the latest version, which includes the necessary authorization checks for PSHARE_CMD messages.
Proactive Monitoring: Monitor network traffic for unusual listener configurations or unexpected traffic redirection patterns originating from the pShare service.
Compensating Controls: Implement strict network segmentation and firewall rules to restrict access to the pShare communication ports to only trusted and authorized internal IP addresses.
Exploitation status
Public Exploit Available: No confirmed public exploit (no Metasploit module, ExploitDB entry, or published proof-of-concept exists).
Analyst recommendation
Given the critical nature of this vulnerability and the potential for complete control over system traffic, immediate remediation is required. Administrators should verify their current version of essential-moos and apply the vendor-provided patch as a matter of urgency to prevent unauthorized runtime configuration changes and potential data interception.
More themoos CVEs
Sources
Originally found and disclosed by Vlatko Kosturjak, per the CVE Program record.
- Pull Request #20 Issue tracker
- Proposed fix commit (pull request not merged) Patch commit
- github.com
- Share.cpp (verified sink) Technical analysis
- VulnCheck Advisory: MOOS essential-moos through 10.0.1 pShare Unauthorized Runtime Route Reconfiguration Third-party advisory