CVE-2026-95846High· 8.7▾ TwilightMoquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client's Last-Will message without applying the canWrite authorization and reserved-topic checks used for a normal PUBLISH. A client can conf…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 47.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client's Last-Will message without applying the canWrite authorization and reserved-topic checks used for a normal PUBLISH. A client can configure a Will for a topic that the client is not permitted to write and cause the broker to publish the unauthorized message when the client disconnects unexpectedly. This issue allows unauthorized message injection into restricted topics. This issue is fixed in version 0.18.1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-95848Critical· 9.3Moquette is a lightweight Java MQTT broker
CVE-2026-95847High· 8.8Moquette is a lightweight Java MQTT broker
CVE-2026-95842High· 8.7Moquette is a lightweight Java MQTT broker
CVE-2026-95843High· 8.7Moquette is a lightweight Java MQTT broker
CVE-2026-85724Critical· 9.6Moquette is a lightweight Java MQTT broker
CVE-2026-95845High· 8.7Moquette is a lightweight Java MQTT broker