PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-95847 moquette-io CVE debrief

CVE-2026-95847 is a high-severity vulnerability in Moquette, a lightweight Java MQTT broker. The issue arises from how Moquette handles durable sessions, specifically when a client ID ends in '_meta', leading to a collision between the message map and metadata map. This collision can corrupt queue data, cause message loss or misdelivery, and potentially expose queued content across sessions. The vulnerability is fixed in version 0.18.1.

Vendor
moquette-io
Product
moquette
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-23
Original CVE updated
2026-09-28
Advisory published
2026-09-23
Advisory updated
2026-09-28

Who should care

Defenders responsible for MQTT brokers and applications using Moquette should assess their exposure and prioritize updating to version 0.18.1 or later to prevent potential data corruption and message exposure.

Why it matters

CVE-2026-95847 is a high-severity vulnerability in Moquette that can lead to data corruption, message loss, and potential exposure of queued content. Defenders should prioritize updating to version 0.18.1 or later and assess their exposure.

  • Potential data corruption in Moquette queues
  • Message loss or misdelivery due to map collisions
  • Exposure of queued content across sessions
  • Verification of Moquette version and inventory checks required

Technical summary

The vulnerability in Moquette arises from the way it handles durable sessions. When a client ID ends in '_meta', it can cause a collision between the message map and metadata map, leading to data corruption and potential exposure of queued content. This issue is addressed in version 0.18.1. Defenders should prioritize updating Moquette to version 0.18.1 or later to prevent potential data corruption and message exposure. MQTT brokers and applications using Moquette should assess their exposure and verify the version in use, focusing on identifying and mitigating potential impacts on queue data integrity and message delivery.

Defensive priority

Defenders should prioritize updating Moquette to version 0.18.1 or later to prevent potential data corruption and message exposure. MQTT brokers and applications using Moquette should assess their exposure and verify the version in use.

Recommended defensive actions

  • Update Moquette to version 0.18.1 or later
  • Assess exposure of MQTT brokers and applications using Moquette
  • Verify the version of Moquette in use
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, its impact, and the fix in version 0.18.1. GitHub references offer additional context on the patches and release notes. Defenders should verify the Moquette version in use, assess exposure, and prioritize updating to version 0.18.1 or later. Evidence from the CVE Program and NVD detail page supports this guidance, emphasizing the need for immediate attention to prevent potential data corruption and message exposure.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-95847 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-95847

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-95847 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-95847

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.