Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-33217

Опубликовано: 25 мар. 2026
Источник: nvd
CVSS3: 7.1
CVSS3: 6.5
CVSS3: 8.1
EPSS Низкий

Описание

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using ACLs on message subjects, these ACLs were not applied in the $MQTT.> namespace, allowing MQTT clients to bypass ACL checks for MQTT subjects. Versions 2.11.15 and 2.12.6 contain a fix. No known workarounds are available.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:linuxfoundation:nats-server:*:*:*:*:*:*:*:*
Версия до 2.11.15 (исключая)
cpe:2.3:a:linuxfoundation:nats-server:*:*:*:*:*:*:*:*
Версия от 2.12.0 (включая) до 2.12.6 (исключая)

EPSS

Процентиль: 18%
0.00259
Низкий

7.1 High

CVSS3

6.5 Medium

CVSS3

8.1 High

CVSS3

Дефекты

CWE-863
CWE-425

Связанные уязвимости

CVSS3: 7.1
ubuntu
5 месяцев назад

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using ACLs on message subjects, these ACLs were not applied in the `$MQTT.>` namespace, allowing MQTT clients to bypass ACL checks for MQTT subjects. Versions 2.11.15 and 2.12.6 contain a fix. No known workarounds are available.

CVSS3: 8.1
redhat
5 месяцев назад

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using ACLs on message subjects, these ACLs were not applied in the `$MQTT.>` namespace, allowing MQTT clients to bypass ACL checks for MQTT subjects. Versions 2.11.15 and 2.12.6 contain a fix. No known workarounds are available.

CVSS3: 7.1
debian
5 месяцев назад

NATS-Server is a High-Performance server for NATS.io, a cloud and edge ...

CVSS3: 7.1
github
5 месяцев назад

NATS allows MQTT clients to bypass ACL checks

EPSS

Процентиль: 18%
0.00259
Низкий

7.1 High

CVSS3

6.5 Medium

CVSS3

8.1 High

CVSS3

Дефекты

CWE-863
CWE-425