CVE-2026-85435

    Dashboard / Vulnerabilities / CVE-2026-85435

    CVE-2026-85435

    Published: 3 Sept 2026Last Modified: 10 Sept 2026

    Summary: MOOS-IvP through 24.8.1 uFldNodeBroker Unauthenticated Shore Route Enrollment

    Details: MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the source of TRY_SHORE_HOST messages on the vehicle bus, allowing any publisher to enroll attacker-controlled shore routes. Attackers can publish malicious shore route messages to receive bridged vehicle traffic including sensor data and control information.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2026-85435 | CVE-DB