CVE-2017-7650: Debian Linux

Medium severity, CVSS 6.5. EPSS: 2.5% chance of exploitation in the next 30 days.

In Mosquitto before 1.4.12, pattern based ACLs can be bypassed by clients that set their username/client id to '#' or '+'. This allows locally or remotely connected clients to access MQTT topics that they do have the rights to. The same issue may be present in third party authentication/access control plugins for Mosquitto.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Eclipse Mosquitto: before 1.4.12 (fixed in 1.4.12)

Published 2017-09-11. Last modified 2026-06-17.