CVE-2026-85724
9.6 CRITICALpublic exploit availablePublished 2026-09-23 · Updated 2026-09-25
AI risk analysis
- Summary
- The flaw allows a client to substitute their identity into MQTT topic filters, potentially gaining unauthorized access to other tenants' data. This is due to direct substitution of client ID and username values into pattern-based ACL rules.
- Exploitability
- Exploitation is moderately hard as it requires a client to use + or # in their identity, but preconditions are minimal.
- Blast radius
- If exploited, the attacker could gain cross-tenant read and write access, leading to significant data breaches.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to moquette 0.18.1 or later.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when pattern-based ACL rules are configured, AuthorizationsCollector.canDoOperation substitutes client ID and username values directly into rules containing %c or %u and then treats the result as an MQTT topic filter. A client that uses + or # in either identity can broaden the substituted filter and gain cross-tenant read and write access. A # identity can also produce an invalid filter that triggers a NullPointerException in Topic.match and disrupts session processing. This issue is fixed in version 0.18.1.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Weaknesses
CWE-155, CWE-863
Vendors
moquette
Products
moquette
Public exploit & PoC references
- https://github.com/moquette-io/moquette/commit/b4a98bb3f3425ece476ed073aa080c627c1239af[Patch]
- https://github.com/moquette-io/moquette/releases/tag/v0.18.1[Release Notes]
- https://github.com/moquette-io/moquette/security/advisories/GHSA-5f42-97gr-vfhq[Exploit, Mitigation, Vendor Advisory]
- https://github.com/moquette-io/moquette/security/advisories/GHSA-5f42-97gr-vfhq[Exploit, Mitigation, Vendor Advisory]
All references
- https://github.com/moquette-io/moquette/commit/b4a98bb3f3425ece476ed073aa080c627c1239af
- https://github.com/moquette-io/moquette/releases/tag/v0.18.1
- https://github.com/moquette-io/moquette/security/advisories/GHSA-5f42-97gr-vfhq
- https://github.com/moquette-io/moquette/security/advisories/GHSA-5f42-97gr-vfhq
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-95848PoC
- HIGHCVE-2026-100552PoC
- HIGHCVE-2026-100623PoC
- CRITICALCVE-2026-100721PoC
- CRITICALCVE-2026-101000PoC
- HIGHCVE-2026-101062PoC
- MEDIUMCVE-2026-52743PoC
- LOWCVE-2026-55060PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.