Skip to content
Threat Feed
critical advisory

Unauthenticated Bridge Redirection in MOOS-IvP uFldShoreBroker

MOOS-IvP uFldShoreBroker through version 24.8.1 is vulnerable to unauthorized route manipulation via forged node ping messages, enabling attackers to redirect data to arbitrary network locations.

CVE search metadata

CVE search record: CVE-2026-85434. Severity: critical. CVSS: 9.1. KEV: no. Product: uFldShoreBroker (<= 24.8.1). Brief: Unauthenticated Bridge Redirection in MOOS-IvP uFldShoreBroker. Brief link: https://feed.craftedsignal.io/briefs/2026-09-moos-ivp-vulnerability/

What's new

  • 1. added coverage for uFldShoreBroker (<= 24.8.1) Sep 3, 23:29 via nvd

MOOS-IvP uFldShoreBroker, a component used for coordinating data bridging in autonomous marine vehicle simulations and control systems, contains a critical security vulnerability (CVE-2026-85434). The flaw exists because the software fails to authenticate 'NODE_BROKER_PING' messages before processing them to establish outbound bridge routes. By publishing a crafted 'NODE_BROKER_PING' message containing malicious 'HostRecord' data, an attacker can coerce the broker into redirecting variable traffic to arbitrary attacker-controlled IP addresses. This effectively allows an adversary to intercept, modify, or drop sensitive operational data flowing across the bridge, potentially impacting the mission integrity of connected autonomous nodes. This vulnerability affects all versions of uFldShoreBroker up to and including 24.8.1. Defenders must identify any instances of this software within their network segments and restrict message publication access to authorized nodes only.

Impact

Successful exploitation allows for the redirection of sensitive telemetry and control variables to malicious infrastructure. In maritime autonomous systems, this can lead to operational disruption, loss of communication with remote vessels, or the injection of false navigational or control data, potentially causing physical damage or loss of autonomous assets.

Recommendation

  • Upgrade uFldShoreBroker to a patched version beyond 24.8.1 immediately upon vendor availability.
  • Implement strict network segmentation for systems running MOOS-IvP to limit the exposure of the messaging bus to unauthorized participants.
  • Audit and restrict permissions for publishing 'NODE_BROKER_PING' messages to known, authenticated, and trusted sources within the MOOS-IvP network.
  • Monitor network traffic for unexpected outbound connections from nodes running uFldShoreBroker to unknown or non-standard external destinations.

Immediate actions

Restrict network access to MOOS-IvP messaging components

IT Operations 24h

Mitigations

Upgrade uFldShoreBroker when vendor provides fixed version beyond 24.8.1

immediate IT Operations

CVE-2026-85434