MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the source of TRY_SHORE_HOST messages on the vehicle bus, allowing any publisher to enroll attacker-controlled shore routes. Attackers can publish malicious shore route messages to receive bridged vehicle traffic including sensor data and control information.
{
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-345"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85435.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-85435.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "205105793825430045765894660149070176882",
"length": 721
},
"id": "CVE-2026-85435-17eb9c04",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/moos-ivp/moos-ivp/commit/477be7e91bf220185d55e5a2a9dba16dbde32c3f",
"target": {
"file": "ivp/src/lib_mbutil/ReleaseInfo.cpp",
"function": "showReleaseInfo"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"71475089026327374911439190140854268963",
"288109013441206453595364179806630758895",
"108583411300907172617501463823770114997",
"17171581118612079636848717634386598063"
],
"threshold": 0.9
},
"id": "CVE-2026-85435-703d642b",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/moos-ivp/moos-ivp/commit/477be7e91bf220185d55e5a2a9dba16dbde32c3f",
"target": {
"file": "ivp/src/pMarineViewer/main.cpp"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "118965062358282729215132681048895208743",
"length": 2942
},
"id": "CVE-2026-85435-9c0df7cc",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/moos-ivp/moos-ivp/commit/477be7e91bf220185d55e5a2a9dba16dbde32c3f",
"target": {
"file": "ivp/src/pMarineViewer/main.cpp",
"function": "main"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"221566291563585211413467636629101977597",
"69881209764151303531923320257498233409",
"153719805825789704065453832941046288979",
"196362707078072643545117675400601289962"
],
"threshold": 0.9
},
"id": "CVE-2026-85435-b57c450a",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/moos-ivp/moos-ivp/commit/477be7e91bf220185d55e5a2a9dba16dbde32c3f",
"target": {
"file": "ivp/src/lib_mbutil/ReleaseInfo.cpp"
}
}
]
"2026-09-06T08:00:49Z"