← Back to search

CVE-2026-95848

9.1 CRITICALpublic exploit available

Published 2026-09-23 · Updated 2026-09-28

AI risk analysis

Summary
The flaw allows the MQTT broker to start without configured authentication or authorization, potentially exposing the system to unauthorized access.
Exploitability
Exploitation is relatively easy if the class name is misspelled or if there are missing dependencies, as these conditions can disable critical security features.
Blast radius
If exploited, this could lead to unauthorized access to the MQTT broker, potentially allowing malicious actors to publish or subscribe to topics without proper authorization.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to moquette version 0.18.1 or later.
auth-bypassmqttjava

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when a configured authenticator or authorizator class cannot be loaded, Server.initializeAuthenticator and Server.initializeAuthorizatorPolicy treat the failure as though no custom class was configured and fall back to AcceptAllAuthenticator or PermitAllAuthorizatorPolicy. A misspelled class name, missing dependency, constructor failure, or classpath problem can therefore start the broker with authentication or authorization disabled even though the operator configured those controls. This issue is fixed in version 0.18.1.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Weaknesses

CWE-636

Vendors

moquette

Products

moquette

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.