MOOS-IvP uMemWatch through 24.8.1 constructs shell commands from attacker-chosen MOOS client names without sanitization. Attackers can inject shell metacharacters into client names to execute arbitrary commands as the uMemWatch process user through unquoted redirection targets in system calls.
{
"cwe_ids": [
"CWE-78"
],
"cna_assigner": "VulnCheck",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85426.json"
}[
{
"target": {
"file": "ivp/src/lib_mbutil/ReleaseInfo.cpp",
"function": "showReleaseInfo"
},
"deprecated": false,
"id": "CVE-2026-85426-17eb9c04",
"signature_version": "v1",
"digest": {
"function_hash": "205105793825430045765894660149070176882",
"length": 721.0
},
"signature_type": "Function",
"source": "https://github.com/moos-ivp/moos-ivp/commit/477be7e91bf220185d55e5a2a9dba16dbde32c3f"
},
{
"target": {
"file": "ivp/src/pMarineViewer/main.cpp"
},
"deprecated": false,
"id": "CVE-2026-85426-703d642b",
"signature_version": "v1",
"digest": {
"line_hashes": [
"71475089026327374911439190140854268963",
"288109013441206453595364179806630758895",
"108583411300907172617501463823770114997",
"17171581118612079636848717634386598063"
],
"threshold": 0.9
},
"signature_type": "Line",
"source": "https://github.com/moos-ivp/moos-ivp/commit/477be7e91bf220185d55e5a2a9dba16dbde32c3f"
},
{
"target": {
"file": "ivp/src/pMarineViewer/main.cpp",
"function": "main"
},
"deprecated": false,
"id": "CVE-2026-85426-9c0df7cc",
"signature_version": "v1",
"digest": {
"function_hash": "118965062358282729215132681048895208743",
"length": 2942.0
},
"signature_type": "Function",
"source": "https://github.com/moos-ivp/moos-ivp/commit/477be7e91bf220185d55e5a2a9dba16dbde32c3f"
},
{
"target": {
"file": "ivp/src/lib_mbutil/ReleaseInfo.cpp"
},
"deprecated": false,
"id": "CVE-2026-85426-b57c450a",
"signature_version": "v1",
"digest": {
"line_hashes": [
"221566291563585211413467636629101977597",
"69881209764151303531923320257498233409",
"153719805825789704065453832941046288979",
"196362707078072643545117675400601289962"
],
"threshold": 0.9
},
"signature_type": "Line",
"source": "https://github.com/moos-ivp/moos-ivp/commit/477be7e91bf220185d55e5a2a9dba16dbde32c3f"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-85426.json"
"2026-09-06T08:00:48Z"