OCTOBER 11, 2026
Live Feed
Back to database
Case File

CVE-2026-85058

HIGH · CVSS 7.5 EPSS 0.45% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-18 · Last synced 2026-10-11

CyberRota Analysis

AI-Generated

Moquette MQTT broker versions prior to 0.18.1 are vulnerable due to a flaw in the PostOffice.publishWill function, which allows remote clients to publish unauthorized messages to ACL-protected topics when anonymous access is enabled. This can lead to the injection of attacker-controlled messages, potentially compromising the integrity of the messaging system. Organizations using Moquette in environments where anonymous access is permitted should prioritize upgrading to version 0.18.1 to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-85058
Severity
HIGH
CVSS
7.5
EPSS
0.45%
Office Java

Original NVD Description

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client-controlled Last Will message through publish2Subscribers without invoking the authorizator.canWrite check used by normal PUBLISH paths. When anonymous access is enabled and topic ACLs restrict writes, a remote client can set an ACL-protected topic as the Last Will Topic during CONNECT and perform an abnormal client disconnect, causing the broker to inject attacker-controlled messages into a topic for which the client lacks write permission. This issue is fixed in version 0.18.1.