Junglewise Threat Intelligence

CVE-2026-33217: NATS-Server ACL bypass in MQTT namespace

CVE-2026-33217 · Severity: high · CVSS 7.1 · Published 2026-03-25

Technologies: github.com/nats-io/nats-server/v2 (Go), Nats-Io NATS Server, github.com/nats-io/nats-server (Go), Red Hat Multicluster Global Hub. Vendors: Go, Red Hat.

Executive brief

NATS-Server is a high-performance messaging system used for cloud and IoT communications. A security flaw was identified where access control rules (ACLs) were not properly enforced for clients using the MQTT protocol. This could allow an authenticated user to bypass security restrictions and publish or receive messages they are not authorized to access, potentially leading to unauthorized data modification or information disclosure.

Technical details

A vulnerability in NATS-Server's MQTT implementation involves incorrect authorization (CWE-863) when processing message subjects. Specifically, ACLs defined for message subjects were not applied within the '$MQTT.>' namespace. A remote attacker with valid MQTT credentials could exploit this to bypass intended subject-based access restrictions, enabling unauthorized publishing or subscribing to restricted topics. The issue is resolved in NATS-Server versions 2.11.15 and 2.12.6. Red Hat has also released updates for Multicluster Global Hub to address this vulnerability.

Affected products

  • nats-io nats-server < 2.11.15, >= 2.12.0-RC.1, < 2.12.6
  • Red Hat Multicluster Global Hub 1.4.5, 1.5.4, 1.6.2

Timeline

  • 2026-03-24: advisory: Vendor advisory published by NATS.io
  • 2026-03-25: disclosed: CVE published to NVD
  • 2026-05-28: patched: Red Hat released security updates for Multicluster Global Hub 1.5.4
  • 2026-06-01: patched: Red Hat released security updates for Multicluster Global Hub 1.4.5

References

Related threats