External risk intelligence

Moquette Broker Access Control Bypass via Malformed Client Identity

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-85724

Moquette is an MQTT broker, which is a network-accessible service designed to act as a central hub for messaging between IoT devices, applications, and edge services. Such brokers are frequently deployed to be reachable over networks to facilitate device communication, making them a common part of the exposed infrastructure in many connectivity-oriented environments.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Moquette, a Java-based MQTT broker, which could allow unauthorized access to data across different tenants. This issue stems from how the broker handles specially crafted client identifiers or usernames when configured with pattern-based access rules, potentially leading to a compromise of data confidentiality and integrity. The main concern is confirming relevance and exposure within your environment.

  • Broker vulnerability allows cross-tenant data access.
  • Critical flaw impacts secure messaging infrastructure.
  • Confirm relevance and assess your exposure.

Attack Path

How an attacker could exploit the issue

An attacker could gain unauthorized access to sensitive data and potentially disrupt service by exploiting a vulnerability in Moquette's authorization system. This occurs when pattern-based access control rules are used, and an attacker can manipulate their client ID or username to include special characters. These characters are then processed incorrectly, allowing the attacker to bypass intended restrictions and interact with topics they shouldn't, or even cause the broker to crash.

  • Requires authenticated access.
  • Triggers vulnerability with crafted client identity.
  • Leads to data access and service disruption.

Live Threat

Current exploitation, exposure, and threat context

When pattern-based access control rules are configured, an attacker could exploit this vulnerability by using special characters in their client ID or username. This could allow them to gain unauthorized read and write access to data across different tenants, or to disrupt service by causing a NullPointerException.

  • Cross-tenant data read/write access.
  • Impersonation via client ID/username manipulation.
  • Service disruption via unexpected errors.

Operational Fix

Recommended remediation, mitigation, and detection steps

Teams responsible for Moquette, a Java MQTT broker, should focus on identifying instances and assessing their criticality. The initial steps involve locating all deployments of Moquette, determining their network reachability, and confirming their business importance. Subsequently, the accountable owner must be identified to plan remediation efforts based on the assessed risk.

  • App/Platform teams likely own Moquette.
  • Verify Moquette deployment reachability and criticality.
  • Plan remediation based on risk and ownership.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Moquette?

Moquette is a lightweight, Java-based MQTT broker. It functions as a central message hub that facilitates communication between IoT devices, applications, and edge services, effectively acting as the traffic controller for data moving across a network.

What does CWE-863 mean for CVE-2026-85724?

CWE-863 refers to improper authorization. In this CVE, the broker incorrectly substitutes client identifiers into access rules. This logic error allows a user to manipulate their identity to bypass security restrictions, granting them unintended read or write access to data belonging to other tenants.

How can an attacker trigger this vulnerability?

An attacker triggers the flaw by using specific characters, such as '+' or '#', within their client ID or username. This only happens when pattern-based access control rules are active. If you are not using these specific pattern-based rules, the substitution logic that leads to this bypass is not invoked.

Is my Moquette deployment relevant here?

According to Halo Surface Signal, Moquette is often deployed as a network-accessible service to support IoT connectivity, making it a common part of exposed infrastructure. You should consider your instance relevant if it is reachable over a network and uses pattern-based access rules.

How do I respond to this vulnerability?

Start by locating all Moquette instances within your environment and verifying if they are configured with pattern-based access rules. Once identified, work with the team responsible for those assets to plan an upgrade to version 0.18.1 or later, which contains the necessary fix.

References