# CVE-2026-85431

## Summary

- **CVE ID:** CVE-2026-85431
- **Severity:** HIGH
- **CVSS Score:** 8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-345
- **Published:** Sep 3, 2026
- **Last Modified:** Sep 4, 2026

## Description

MOOS essential-moos through version 10.0.1 contains an unauthenticated UDP packet injection vulnerability in pMOOSBridge when configured with UDPListen. Attackers can send crafted UDP packets to the configured port to inject arbitrary variables into the local MOOS community with spoofed source and community identifiers.

## Affected Products

- themoos — essential-moos (0)

## References

- [CNA](https://github.com/themoos/essential-moos/pull/19)
- [CNA](https://github.com/themoos/essential-moos/commit/d8441eac57d04ee89e7b82723480d10a558b45d6)
- [CNA](https://github.com/themoos/essential-moos)
- [CNA](https://github.com/themoos/essential-moos/blob/b897ea86dba8b61412dc48ac0cfb5ff34cdaf5f6/Essentials/pMOOSBridge/MOOSUDPLink.cpp#L21)
- [CNA](https://www.vulncheck.com/advisories/moos-essential-moos-through-10.0.1-pmoosbridge-unauthenticated-udp-packet-injection)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 1.90%
- **EPSS Percentile:** 78.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-09._