| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9jjc-fw8x-fmwx | io.moquette:moquette-broker has a Missing Authorization issue |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 24 Sep 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 21 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Moquette-io
Moquette-io moquette |
|
| Vendors & Products |
Moquette-io
Moquette-io moquette |
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client-controlled Last Will message through publish2Subscribers without invoking the authorizator.canWrite check used by normal PUBLISH paths. When anonymous access is enabled and topic ACLs restrict writes, a remote client can set an ACL-protected topic as the Last Will Topic during CONNECT and perform an abnormal client disconnect, causing the broker to inject attacker-controlled messages into a topic for which the client lacks write permission. This issue is fixed in version 0.18.1. | |
| Title | Moquette: Missing Authorization in io.moquette:moquette-broker | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-22T15:14:00.736Z
Reserved: 2026-09-02T21:21:01.774Z
Link: CVE-2026-85058
Updated: 2026-09-22T15:13:47.795Z
Status : Received
Published: 2026-09-18T18:17:17.447
Modified: 2026-09-22T16:18:04.153
Link: CVE-2026-85058
No data.
OpenCVE Enrichment
Updated: 2026-09-21T10:04:16Z
Github GHSA