PT-2026-97391 · Moquette · Moquette
CVE-2026-85724
·
Published
2026-09-23
·
Updated
2026-09-25
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Moquette versions prior to 0.18.1
Description
When pattern-based ACL rules are configured, the
AuthorizationsCollector.canDoOperation() function substitutes client ID and username values directly into rules containing %c or %u and treats the result as an MQTT topic filter. A client using + or # in their identity can broaden the substituted filter to gain cross-tenant read and write access. Additionally, using a # identity can produce an invalid filter that triggers a NullPointerException in Topic.match(), disrupting session processing. Other issues include a StringIndexOutOfBoundsException in SharedSubscriptionUtils.extractShareName() via malformed $share/grp subscriptions, StackOverflowError from deeply nested topics, and potential memory exhaustion due to unbounded queues in BrokerInterceptor. Furthermore, Last-Will topics are published via PostOffice.publishWill() without the standard authorization checks used for normal publications, and a namespace collision in H2PersistentQueue can lead to cross-session durable corruption. The system may also fail-open if the authenticator or authorizator class fails to load.Recommendations
Update to version 0.18.1.
As a temporary workaround, reject any
clientId or username containing + or # characters during the CONNECT phase.
Restrict the use of the AuthorizationsCollector.canDoOperation() function by ensuring pattern-based ACLs do not rely on unvalidated client identities.Exploit
Fix
Incorrect Authorization
Improper Neutralization of Wildcards
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Moquette