Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 05 Sep 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 04 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Moos-ivp
Moos-ivp moos-ivp |
|
| Vendors & Products |
Moos-ivp
Moos-ivp moos-ivp |
Thu, 03 Sep 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MOOS-IvP through 24.8.1 contains a remote code execution vulnerability in alogsplit's SplitHandler::handlePreCheckSplitDir() function that fails to sanitize shell metacharacters in log file pathnames. Attackers can embed shell syntax in log file names or the --dir parameter to execute arbitrary commands with the privileges of the operator running alogsplit. | |
| Title | MOOS-IvP through 24.8.1 alogsplit Command Injection via Input Pathname | |
| Weaknesses | CWE-78 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-05T02:26:42.375Z
Reserved: 2026-09-03T19:50:57.231Z
Link: CVE-2026-85439
Updated: 2026-09-05T02:26:38.457Z
Status : Received
Published: 2026-09-03T23:17:23.427
Modified: 2026-09-05T03:17:24.433
Link: CVE-2026-85439
No data.
OpenCVE Enrichment
Updated: 2026-09-04T15:21:21Z