PT-2026-95583 · Moquette · Moquette

CVE-2026-85058

·

Published

2026-09-18

·

Updated

2026-09-24

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Moquette versions prior to 0.18.1
Description Moquette fails to enforce Access Control List (ACL) write permission checks when publishing Last Will and Testament messages on behalf of disconnected clients. While standard publishing paths correctly invoke the authorizator.canWrite() check, the path used for Will messages—specifically fireWill(), publishWill(), and publish2Subscribers()—bypasses this authorization.
When anonymous access is enabled (which is the default setting allow anonymous=true), a remote unauthenticated attacker can set an ACL-protected topic as the Last Will Topic during the CONNECT phase. By subsequently performing an abnormal disconnect (such as a TCP RST), the attacker can force the broker to inject arbitrary messages into a topic for which they lack write permissions. This authorization bypass can be leveraged to deliver malicious payloads to subscribers; for instance, if a subscriber deserializes the message payload using ObjectInputStream.readObject(), it could lead to Remote Code Execution (RCE) via deserialization gadgets.
Recommendations Update Moquette to version 0.18.1. As a temporary mitigation, disable anonymous access by setting allow anonymous to false in the configuration to restrict who can establish connections and set Will messages.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85058
GHSA-9JJC-FW8X-FMWX

Affected Products

Moquette