
MQTT ブローカー Moquette の CVE-2026-95848(CVSS 9.1)を解説しました。認証・認可のクラスが読み込めないと全許可に倒れてしまう問題で、0.18.1 で修正されています。 https://ai-news.autoarticles.net/article/post_1790693178593_75bvgg
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when a configured authenticator or authorizator class cannot be loaded, Server.initializeAuthenticator and Server.initializeAuthorizatorPolicy treat the failure as though no custom class was configured and fall back to AcceptAllAuthenticator or PermitAllAuthorizatorPolicy. A misspelled class name, missing dependency, constructor failure, or classpath problem can therefore start the broker with authentication or authorization disabled even though the operator configured those controls. This issue is fixed in version 0.18.1.
Priority
LOW
Exploitation
NONE
PoC
YES
Patch
AVAILABLE
Momentum
NONE
If you run products in this scope, you should treat this CVE as relevant to your environment.

MQTT ブローカー Moquette の CVE-2026-95848(CVSS 9.1)を解説しました。認証・認可のクラスが読み込めないと全許可に倒れてしまう問題で、0.18.1 で修正されています。 https://ai-news.autoarticles.net/article/post_1790693178593_75bvgg
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | moquette | moquette | - | - | - |