Command Injection in MOOS-IvP uMemWatch
MOOS-IvP uMemWatch through version 24.8.1 is vulnerable to command injection due to improper sanitization of MOOS client names, allowing arbitrary code execution.
CVE search metadata
CVE search record: CVE-2026-85426. Severity: critical. CVSS: 9.8. KEV: no. Product: uMemWatch (<= 24.8.1). Brief: Command Injection in MOOS-IvP uMemWatch. Brief link: https://feed.craftedsignal.io/briefs/2026-09-moos-ivp-umemwatch-injection/
MOOS-IvP uMemWatch, a component used in the MOOS-IvP autonomous vehicle control software suite, is susceptible to a critical command injection vulnerability (CVE-2026-85426) affecting all versions up to and including 24.8.1. The vulnerability arises because the application fails to properly sanitize user-supplied MOOS client names before incorporating them into shell commands invoked via system calls. By crafting a MOOS client name containing shell metacharacters, an attacker can escape the intended command string and execute arbitrary commands with the privileges of the user running the uMemWatch process. This vulnerability is particularly concerning in autonomous system environments where uMemWatch often runs with elevated privileges to monitor system integrity. Defenders should prioritize updating to the patched version of the software and monitor for unexpected child processes spawned by the uMemWatch binary.
Impact
Successful exploitation allows for full command execution on the host running the uMemWatch process. Given the role of MOOS-IvP in autonomous vehicle systems, this could lead to unauthorized control of system resources, manipulation of sensor data, or total system compromise, resulting in mission failure or physical equipment hazards.
Recommendation
- Patch CVE-2026-85426 by upgrading the MOOS-IvP suite to a version greater than 24.8.1 immediately.
- Audit process execution logs for instances where uMemWatch spawns unexpected shells or system utilities (e.g., sh, bash, python).
- Enforce principle of least privilege by running the uMemWatch process with a dedicated, non-privileged service account.
Immediate actions
Upgrade MOOS-IvP software to version > 24.8.1
Mitigations
Upgrade to latest version
CVE-2026-85426