{"id":"CVE-2026-85724","summary":"Moquette pattern ACL wildcard injection allows cross-tenant authorization bypass","details":"Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when pattern-based ACL rules are configured, AuthorizationsCollector.canDoOperation substitutes client ID and username values directly into rules containing %c or %u and then treats the result as an MQTT topic filter. A client that uses + or # in either identity can broaden the substituted filter and gain cross-tenant read and write access. A # identity can also produce an invalid filter that triggers a NullPointerException in Topic.match and disrupts session processing. This issue is fixed in version 0.18.1.","aliases":["CVE-2026-95842","CVE-2026-95843","CVE-2026-95844","CVE-2026-95845","CVE-2026-95846","CVE-2026-95847","CVE-2026-95848","GHSA-5f42-97gr-vfhq"],"modified":"2026-09-24T08:22:25.673387Z","published":"2026-09-23T16:29:36.296Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85724.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-155","CWE-863"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85724.json"},{"type":"FIX","url":"https://github.com/moquette-io/moquette/commit/b4a98bb3f3425ece476ed073aa080c627c1239af"},{"type":"WEB","url":"https://github.com/moquette-io/moquette/releases/tag/v0.18.1"},{"type":"ADVISORY","url":"https://github.com/moquette-io/moquette/security/advisories/GHSA-5f42-97gr-vfhq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85724"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/moquette-io/moquette","events":[{"introduced":"0"},{"fixed":"e8ce83336acce69d8e9c11c98805217aa156a16b"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"0.18.1"}],"source":"AFFECTED_FIELD"}}],"versions":["v0.18.0","0.18.0","last_gradle","v0.12.1","v0.12","v0.11","second_try_with_osgi_giveup","last_with_maven","v0.10","before_sofia2","v0.9","v0.8","last_with_ringbuffer","0.7","last_osgi"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-85724.json","vanir_signatures_modified":"2026-09-24T08:22:25Z","vanir_signatures":[{"source":"https://github.com/moquette-io/moquette/commit/e8ce83336acce69d8e9c11c98805217aa156a16b","target":{"file":"broker/src/main/java/io/moquette/broker/Server.java"},"deprecated":false,"digest":{"line_hashes":["264460424198365981025294149882277014898","11410191927348774178838709852851310256","273802157253247414129958982189405529275","315296026132642631038163665576809441438"],"threshold":0.9},"id":"CVE-2026-85724-dd85d397","signature_type":"Line","signature_version":"v1"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"}]}