{"id":"CVE-2026-95848","published":"2026-09-23T17:17:21.947","lastModified":"2026-09-28T15:23:06.303","description":"Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when a configured authenticator or authorizator class cannot be loaded, Server.initializeAuthenticator and Server.initializeAuthorizatorPolicy treat the failure as though no custom class was configured and fall back to AcceptAllAuthenticator or PermitAllAuthorizatorPolicy. A misspelled class name, missing dependency, constructor failure, or classpath problem can therefore start the broker with authentication or authorization disabled even though the operator configured those controls. This issue is fixed in version 0.18.1.","cvssScore":9.1,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","cwes":["CWE-636"],"vendors":["moquette"],"products":["moquette"],"references":[{"url":"https://github.com/moquette-io/moquette/commit/14a2f4fd280c8f6a791600c306cbccecb7c67007","tags":["Patch"]},{"url":"https://github.com/moquette-io/moquette/pull/967","tags":["Patch"]},{"url":"https://github.com/moquette-io/moquette/releases/tag/v0.18.1","tags":["Release Notes"]},{"url":"https://github.com/moquette-io/moquette/security/advisories/GHSA-5f42-97gr-vfhq","tags":["Exploit","Mitigation","Vendor Advisory"]},{"url":"https://github.com/moquette-io/moquette/security/advisories/GHSA-5f42-97gr-vfhq","tags":["Exploit","Mitigation","Vendor Advisory"]}],"exploitRefs":[{"url":"https://github.com/moquette-io/moquette/commit/14a2f4fd280c8f6a791600c306cbccecb7c67007","tags":["Patch"]},{"url":"https://github.com/moquette-io/moquette/pull/967","tags":["Patch"]},{"url":"https://github.com/moquette-io/moquette/releases/tag/v0.18.1","tags":["Release Notes"]},{"url":"https://github.com/moquette-io/moquette/security/advisories/GHSA-5f42-97gr-vfhq","tags":["Exploit","Mitigation","Vendor Advisory"]},{"url":"https://github.com/moquette-io/moquette/security/advisories/GHSA-5f42-97gr-vfhq","tags":["Exploit","Mitigation","Vendor Advisory"]}],"hasPoc":true,"ai":{"summary":"The flaw allows the MQTT broker to start without configured authentication or authorization, potentially exposing the system to unauthorized access.","exploitability":"Exploitation is relatively easy if the class name is misspelled or if there are missing dependencies, as these conditions can disable critical security features.","blast_radius":"If exploited, this could lead to unauthorized access to the MQTT broker, potentially allowing malicious actors to publish or subscribe to topics without proper authorization.","remediation":"Upgrade to moquette version 0.18.1 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["auth-bypass","mqtt","java"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T08:53:56.907Z"}}