Critical severity9.6NVD Advisory· Published Sep 23, 2026
CVE-2026-85724
CVE-2026-85724
Description
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when pattern-based ACL rules are configured, AuthorizationsCollector.canDoOperation substitutes client ID and username values directly into rules containing %c or %u and then treats the result as an MQTT topic filter. A client that uses + or # in either identity can broaden the substituted filter and gain cross-tenant read and write access. A # identity can also produce an invalid filter that triggers a NullPointerException in Topic.match and disrupts session processing. This issue is fixed in version 0.18.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
16- github.com/advisories/GHSA-5f42-97gr-vfhqghsaADVISORY
- github.com/moquette-io/moquette/commit/14a2f4fd280c8f6a791600c306cbccecb7c67007ghsa
- github.com/moquette-io/moquette/commit/26498631e92d50440b4e3ed42fa546253cc4090cghsa
- github.com/moquette-io/moquette/commit/72d6c8257191d2e4b2e3aa11ab25fd09f88c6cb7ghsa
- github.com/moquette-io/moquette/commit/86feb7c31e6fac849c465d8079d08c0e7ef01cdfghsa
- github.com/moquette-io/moquette/commit/affdc71fdba92dc020421678970ae70518fb6da2ghsa
- github.com/moquette-io/moquette/commit/b4a98bb3f3425ece476ed073aa080c627c1239afnvd
- github.com/moquette-io/moquette/commit/c65b3e90fa03e562e2c2fa69c3ee916c2cbfbd2bghsa
- github.com/moquette-io/moquette/commit/ca17e0be19e86d5e291f4532dfdc94616c8e0049ghsa
- github.com/moquette-io/moquette/commit/d77753542e262b7aa573dee3c2b05e44439bbd96ghsa
- github.com/moquette-io/moquette/commit/f5a323fe782d1505c0097498cb22eb6ec6c96973ghsa
- github.com/moquette-io/moquette/pull/957ghsa
- github.com/moquette-io/moquette/pull/958ghsa
- github.com/moquette-io/moquette/pull/959ghsa
- github.com/moquette-io/moquette/releases/tag/v0.18.1nvd
- github.com/moquette-io/moquette/security/advisories/GHSA-5f42-97gr-vfhqnvd
News mentions
0No linked articles in our index yet.