Junglewise Threat Intelligence

CVE-2026-58209: NATS Server MQTT authorization bypass in subscribe deny rules

CVE-2026-58209 · Severity: medium · CVSS 4.3 · Published 2026-07-08

Technologies: Nats-Io NATS Server.

Executive brief

NATS Server is a high-performance messaging system used for cloud and edge computing. A security flaw in its MQTT implementation could allow a user to receive messages from topics they are specifically restricted from accessing. This occurs when messages are delivered via 'retained' message or 'durable replay' features, potentially leading to the unauthorized exposure of sensitive data.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in NATS Server's MQTT protocol handler. The delivery paths for MQTT retained messages and QoS1+ durable replays do not consistently re-verify the concrete original topic against a subscriber's configured 'subscribe deny' rules before transmission. An authenticated attacker with basic subscriber privileges can exploit this to receive messages on restricted topics if those messages are delivered through these specific replay mechanisms. The issue is resolved in versions 2.12.12 and 2.14.3 by ensuring the original topic is rechecked before an MQTT PUBLISH packet is sent.

Affected products

  • nats-io NATS Server < 2.12.12, >= 2.14.0-RC.1, < 2.14.3

Timeline

  • 2026-06-29: patched: Versions 2.12.12 and 2.14.3 released
  • 2026-07-08: advisory: CVE-2026-58209 published

References