PT-2026-97391 · Moquette · Moquette

CVE-2026-85724

·

Published

2026-09-23

·

Updated

2026-09-25

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Moquette versions prior to 0.18.1
Description When pattern-based ACL rules are configured, the AuthorizationsCollector.canDoOperation() function substitutes client ID and username values directly into rules containing %c or %u and treats the result as an MQTT topic filter. A client using + or # in their identity can broaden the substituted filter to gain cross-tenant read and write access. Additionally, using a # identity can produce an invalid filter that triggers a NullPointerException in Topic.match(), disrupting session processing. Other issues include a StringIndexOutOfBoundsException in SharedSubscriptionUtils.extractShareName() via malformed $share/grp subscriptions, StackOverflowError from deeply nested topics, and potential memory exhaustion due to unbounded queues in BrokerInterceptor. Furthermore, Last-Will topics are published via PostOffice.publishWill() without the standard authorization checks used for normal publications, and a namespace collision in H2PersistentQueue can lead to cross-session durable corruption. The system may also fail-open if the authenticator or authorizator class fails to load.
Recommendations Update to version 0.18.1. As a temporary workaround, reject any clientId or username containing + or # characters during the CONNECT phase. Restrict the use of the AuthorizationsCollector.canDoOperation() function by ensuring pattern-based ACLs do not rely on unvalidated client identities.

Exploit

Fix

Incorrect Authorization

Improper Neutralization of Wildcards

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85724
GHSA-5F42-97GR-VFHQ

Affected Products

Moquette