PT-2026-95583 · Moquette · Moquette
CVE-2026-85058
·
Published
2026-09-18
·
Updated
2026-09-24
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Moquette versions prior to 0.18.1
Description
Moquette fails to enforce Access Control List (ACL) write permission checks when publishing Last Will and Testament messages on behalf of disconnected clients. While standard publishing paths correctly invoke the
authorizator.canWrite() check, the path used for Will messages—specifically fireWill(), publishWill(), and publish2Subscribers()—bypasses this authorization.When anonymous access is enabled (which is the default setting
allow anonymous=true), a remote unauthenticated attacker can set an ACL-protected topic as the Last Will Topic during the CONNECT phase. By subsequently performing an abnormal disconnect (such as a TCP RST), the attacker can force the broker to inject arbitrary messages into a topic for which they lack write permissions. This authorization bypass can be leveraged to deliver malicious payloads to subscribers; for instance, if a subscriber deserializes the message payload using ObjectInputStream.readObject(), it could lead to Remote Code Execution (RCE) via deserialization gadgets.Recommendations
Update Moquette to version 0.18.1.
As a temporary mitigation, disable anonymous access by setting
allow anonymous to false in the configuration to restrict who can establish connections and set Will messages.Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Moquette