Security Advisory

CVE-2026-85435

9.1
CRITICAL

Vulnerability Description

MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the source of TRY_SHORE_HOST messages on the vehicle bus, allowing any publisher to enroll attacker-controlled shore routes. Attackers can publish malicious shore route messages to receive bridged vehicle traffic including sensor data and control information.
Published Date September 3, 2026
Official Source NIST NVD Advisory