OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-95846

HIGH · CVSS 7.5 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The vulnerability affects the Moquette Java MQTT broker, where the PostOffice.publishWill function improperly handles authorization checks, allowing clients to publish Last-Will messages to restricted topics without permission. This can lead to unauthorized message injection, potentially compromising the integrity of the messaging system. Organizations using affected versions of Moquette should prioritize upgrading to version 0.18.1 to mitigate the risk of unauthorized access and message manipulation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-95846
Severity
HIGH
CVSS
7.5
EPSS
0.27%
Office Java

Original NVD Description

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client's Last-Will message without applying the canWrite authorization and reserved-topic checks used for a normal PUBLISH. A client can configure a Will for a topic that the client is not permitted to write and cause the broker to publish the unauthorized message when the client disconnects unexpectedly. This issue allows unauthorized message injection into restricted topics. This issue is fixed in version 0.18.1.

Related CVEs

Other vulnerabilities affecting the same vendor(s)