External risk intelligence

Moquette Broker Authentication Bypass via Invalid Configuration.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-95848

Moquette is an MQTT broker designed for messaging between distributed systems. These brokers are frequently deployed as internet-facing or edge services to facilitate communication for IoT devices. Due to this primary role as a communication gateway, public-facing exposure is a common and expected deployment pattern for this technology.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in Moquette, a Java-based message broker, could allow an attacker to bypass authentication and authorization controls if certain configuration classes fail to load. This means that even if security measures were intended to be in place, they might be inadvertently disabled due to configuration errors.

  • Misconfigured security controls could be bypassed.
  • Affects systems handling device communication.
  • Confirm relevance and exposure if using this technology.

Attack Path

How an attacker could exploit the issue

An attacker can bypass authentication and authorization by triggering a server initialization error. This occurs when a configured authenticator or authorizator class cannot be loaded, causing the broker to incorrectly assume no custom security was set. This could allow an unauthenticated attacker to gain unauthorized access to sensitive data or control the broker.

  • No entry authentication required.
  • Misconfigured security class loading.
  • Unauthorized access and data exposure.

Live Threat

Current exploitation, exposure, and threat context

When an authenticator or authorizator class cannot be loaded due to misconfiguration or missing dependencies, the Moquette MQTT broker may fall back to allowing all connections and actions, even when custom security controls were intended. This could impact systems relying on the broker for secure communication.

  • Unauthenticated access to broker functions.
  • Unsecured MQTT communication channels.
  • Unauthorized control of connected devices.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in Moquette MQTT brokers could allow unauthenticated attackers to bypass access controls by exploiting how the broker handles configuration errors for custom authenticators or authorizators. The immediate priority is to identify all instances of Moquette, assess their exposure and business criticality, and then coordinate remediation efforts with the accountable system owners, potentially involving vendor support for updates.

  • Application owners must own this issue.
  • Verify all Moquette broker deployments.
  • Plan for controlled updates and testing.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Moquette software?

Moquette is a lightweight, Java-based MQTT broker. It acts as a messaging intermediary that allows distributed systems and IoT devices to exchange data efficiently. Because it handles message routing between devices, it is often placed at the edge of networks to act as a communication gateway.

What is the vulnerability in CVE-2026-95848?

This issue is categorized as CWE-636, which involves a failure to enforce configuration settings. Specifically, if Moquette fails to load your custom security code—such as an authenticator or authorizator—it defaults to an 'open' state. Instead of halting the startup to prevent risk, the broker incorrectly assumes no security is required, effectively disabling all access controls even if you intended them to be active.

How is this authentication bypass triggered?

The bypass occurs when the broker initialization process fails to load a security class, often due to a typo, missing dependency, or classpath error. Importantly, this is not triggered by a specific malformed packet or malicious request from an attacker; it is a side effect of the broker's failure to start with your intended security configuration. If the broker is running in this degraded state, it will permit unauthorized connections automatically.

Is my instance of Moquette at risk?

According to Halo Surface Signal, Moquette is frequently deployed as an internet-facing or edge service to support IoT communications. If your instance is exposed to the public internet, it faces a higher likelihood of being discovered. Even if internal, any broker configured with custom security classes is potentially affected if those classes fail to load correctly upon startup.

Do I need to update my Moquette broker?

Yes, you should update to version 0.18.1 or later to resolve this behavior. Before updating, verify your current configuration to ensure all custom security classes are correctly defined and that there are no classpath or dependency errors. Testing the update in a controlled environment is recommended to confirm that security controls initialize correctly on startup.

References