{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3amoos-ivpumemwatch/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:moos-ivp:umemwatch:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-85426"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["uMemWatch (\u003c= 24.8.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["MOOS-IvP"],"content_html":"\u003cp\u003eMOOS-IvP uMemWatch, a component used in the MOOS-IvP autonomous vehicle control software suite, is susceptible to a critical command injection vulnerability (CVE-2026-85426) affecting all versions up to and including 24.8.1. The vulnerability arises because the application fails to properly sanitize user-supplied MOOS client names before incorporating them into shell commands invoked via system calls. By crafting a MOOS client name containing shell metacharacters, an attacker can escape the intended command string and execute arbitrary commands with the privileges of the user running the uMemWatch process. This vulnerability is particularly concerning in autonomous system environments where uMemWatch often runs with elevated privileges to monitor system integrity. Defenders should prioritize updating to the patched version of the software and monitor for unexpected child processes spawned by the uMemWatch binary.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full command execution on the host running the uMemWatch process. Given the role of MOOS-IvP in autonomous vehicle systems, this could lead to unauthorized control of system resources, manipulation of sensor data, or total system compromise, resulting in mission failure or physical equipment hazards.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-85426 by upgrading the MOOS-IvP suite to a version greater than 24.8.1 immediately.\u003c/li\u003e\n\u003cli\u003eAudit process execution logs for instances where uMemWatch spawns unexpected shells or system utilities (e.g., sh, bash, python).\u003c/li\u003e\n\u003cli\u003eEnforce principle of least privilege by running the uMemWatch process with a dedicated, non-privileged service account.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T23:24:26Z","date_published":"2026-09-03T23:24:26Z","id":"https://feed.craftedsignal.io/briefs/2026-09-moos-ivp-umemwatch-injection/","summary":"MOOS-IvP uMemWatch through version 24.8.1 is vulnerable to command injection due to improper sanitization of MOOS client names, allowing arbitrary code execution.","title":"Command Injection in MOOS-IvP uMemWatch","url":"https://feed.craftedsignal.io/briefs/2026-09-moos-ivp-umemwatch-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:moos-Ivp:umemwatch:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}