PT-2026-97399 · Moquette · Moquette

·

CVE-2026-95848

·

Published

2026-09-23

·

Updated

2026-09-23

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Moquette versions prior to 0.18.1
Description When a configured authenticator or authorizator class cannot be loaded, the Server.initializeAuthenticator() and Server.initializeAuthorizatorPolicy() functions treat the failure as if no custom class was configured. This causes the system to fall back to AcceptAllAuthenticator or PermitAllAuthorizatorPolicy. Consequently, issues such as misspelled class names, missing dependencies, constructor failures, or classpath problems can result in the broker starting with authentication or authorization disabled, despite the operator's configuration.
Recommendations Update to version 0.18.1.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-95848
GHSA-5F42-97GR-VFHQ

Affected Products

Moquette