PT-2026-97397 · Moquette · Moquette

CVE-2026-95846

·

Published

2026-09-23

·

Updated

2026-09-23

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Moquette versions prior to 0.18.1
Description An issue exists where the PostOffice.publishWill() function publishes a client's Last-Will message without applying the canWrite authorization and reserved-topic checks typically required for a normal PUBLISH operation. This allows a client to configure a Will for a topic they are not permitted to write to, resulting in the broker publishing an unauthorized message upon the client's unexpected disconnection. This leads to unauthorized message injection into restricted topics.
Recommendations Update to version 0.18.1.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-95846
GHSA-5F42-97GR-VFHQ

Affected Products

Moquette