<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:mit:core-Moos:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3amitcore-moos/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 03 Sep 2026 23:24:33 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3amitcore-moos/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass in MOOSDB HTTP Server</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-85428/</link><pubDate>Thu, 03 Sep 2026 23:24:33 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-85428/</guid><description>The MOOSDB HTTP server in core-moos versions 10.4.0 and earlier contains an authentication bypass vulnerability allowing unauthenticated remote attackers to modify MOOS variables via crafted HTTP requests.</description><content:encoded><![CDATA[<p>MOOS core-moos versions up to and including 10.4.0 contain a critical authentication bypass vulnerability within the optional MOOSDB HTTP server component. This service, which facilitates inter-process communication in autonomy-oriented systems, fails to enforce authentication checks for administrative requests. Consequently, unauthenticated remote attackers can send specially crafted HTTP requests to the MOOSDB service port to write, modify, or inject MOOS variables. This vulnerability is particularly severe because it allows for the unauthorized manipulation of system states, including the modification of actuator commands and override parameters. Successful exploitation grants attackers direct control over operational variables, potentially leading to the compromise of system integrity and safety in environments utilizing core-moos for autonomous decision-making.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability carries a CVSS v3.1 base score of 9.8. Exploitation could allow attackers to gain unauthorized control over system operations by injecting or modifying MOOS variables. This poses a significant risk to systems in marine robotics, autonomous vehicle research, and other sectors relying on core-moos, where unauthorized actuator changes could lead to loss of control, physical damage, or mission failure.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade core-moos to the latest patched version when available to remediate CVE-2026-85428.</li>
<li>Implement network-level segmentation to restrict access to the MOOSDB HTTP server port (default 9000-9005 range) to authorized management IPs only.</li>
<li>Audit network traffic for unauthorized HTTP traffic directed at the MOOSDB service port.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>