CVE-2026-85724Critical· 9.6▾ AbyssalPoC availableMoquette is a lightweight Java MQTT broker. Prior to 0.18.1, when pattern-based ACL rules are configured, AuthorizationsCollector.canDoOperation substitutes client ID and username values directly into rules containing %c or %u and then t…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 52.8 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Exploit / PoC code exists
Last analysed / modified upstream
0.3%
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when pattern-based ACL rules are configured, AuthorizationsCollector.canDoOperation substitutes client ID and username values directly into rules containing %c or %u and then treats the result as an MQTT topic filter. A client that uses + or # in either identity can broaden the substituted filter and gain cross-tenant read and write access. A # identity can also produce an invalid filter that triggers a NullPointerException in Topic.match and disrupts session processing. This issue is fixed in version 0.18.1.
moquette < 0.18.1Upgrade past the affected range:
moquette 0.18.1Affected packages:
io.moquette:moquette-broker <= 0.18.0Patched in:
io.moquette:moquette-broker 0.18.1Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-95848Critical· 9.3Moquette is a lightweight Java MQTT broker
CVE-2026-95847High· 8.8Moquette is a lightweight Java MQTT broker
CVE-2026-95846High· 7.5Moquette is a lightweight Java MQTT broker
CVE-2026-95842High· 7.5Moquette is a lightweight Java MQTT broker
CVE-2026-95843High· 7.5Moquette is a lightweight Java MQTT broker
CVE-2026-95844High· 8.7Moquette is a lightweight Java MQTT broker