Skip to main content
HIGH

CVE-2026-95846

CVSS v3

7.5

HIGH

EPSS Score

0.3 %

exploit probability, as of 2026-09-29

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client's Last-Will message without applying the canWrite authorization and reserved-topic checks used for a normal PUBLISH. A client can configure a Will for a topic that the client is not permitted to write and cause the broker to publish the unauthorized message when the client disconnects unexpectedly. This issue allows unauthorized message injection into restricted topics. This issue is fixed in v

Technical details

Published
2026-09-23
Last Modified
2026-09-25

Frequently asked questions

What is CVE-2026-95846?

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client's Last-Will message without applying the canWrite authorization and reserved-topic checks used for a normal PUBLISH. A client can configure a Will for a topic that the client is not permitted to write and cause the broker to publish the unauthorized message when the client disconnects unexpectedly. This issue allows unauthorized message injection into restricted topics. This issue is fixed in v

Is CVE-2026-95846 actively exploited?

Active exploitation of CVE-2026-95846 has not been confirmed. Its EPSS score was 0.3% on 2026-09-29, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-95846?

CVE-2026-95846 has a CVSS v3 base score of 7.5 (HIGH severity).

Is CVE-2026-95846 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key