core-moos vulnerability

MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect with full publish, subscribe, and database clear privileges. Attackers can bypass the compile-time protocol string check and connect with arbitrary client names to execute privileged operations including DB_CLEAR which resets all variables and clears client mail queues.

Published 3 Sep 2026Updated 5 Sep 20265 sources
CVSS 9.3

Source timeline

CVE record published by NVDView source ↗