CVE-2026-85724 | moquette-io Moquette up to 0.18.0 ACL Topic.match AuthorizationsCollector.canDoOperation client ID/username improper authorization

SecurityVulns

A vulnerability classified as critical has been found in moquette-io Moquette up to 0.18.0. Impacted is the function AuthorizationsCollector.canDoOperation of the file Topic.match of the component ACL. This manipulation of the argument client ID/username causes improper authorization.

This vulnerability is handled as CVE-2026-85724. The attack can be initiated remotely. There is not any exploit available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More