CVE-2026-85451
Received Received - Intake

Remote Process Termination in MOOS Core

Vulnerability report for CVE-2026-85451, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-03

Last updated on: 2026-09-03

Assigner: VulnCheck

Description

MOOS core-moos through 10.4.0 contains a remote process termination vulnerability in the SuicidalSleeper component that uses a hard-coded passphrase for multicast command authorization. Any multicast-reachable peer can enumerate MOOS processes and send termination commands to trigger process shutdown by exploiting the default multicast group and port with the known passphrase.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-03
Last Modified
2026-09-03
Generated
2026-09-04
AI Q&A
2026-09-04
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
moos core-moos to 10.4.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-798 The product contains hard-coded credentials, such as a password or cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

MOOS core-moos through version 10.4.0 has a flaw in the SuicidalSleeper component where a hard-coded passphrase is used for multicast command authorization. This allows any peer within multicast reach to identify MOOS processes and send termination commands, causing unintended shutdowns by using the default multicast group, port, and known passphrase.

Detection Guidance

To detect this vulnerability, scan your network for multicast traffic on the default MOOS multicast group and port used by core-moos. Check for unauthorized termination commands sent to MOOS processes using the known hard-coded passphrase. Monitor process logs for unexpected shutdowns of MOOS components.

Impact Analysis

An attacker on the same multicast network could remotely terminate critical MOOS processes, leading to service disruptions or denial of service. This could affect operations relying on MOOS core-moos, especially in autonomous systems or robotics where process continuity is essential.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA due to unauthorized remote process termination. Unauthorized access to system processes may lead to data processing interruptions or unauthorized modifications, which could violate data integrity and availability requirements under these regulations.

Mitigation Strategies

Immediately disable multicast command authorization in MOOS core-moos or switch to a secure, passphrase-protected method. Restrict multicast group and port access to trusted peers only. Update to a patched version of core-moos if available. Review and terminate any unauthorized MOOS processes detected.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85451. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart