Junglewise Threat Intelligence

CVE-2026-58214: NATS Server MQTT authorization bypass in internal subject subscription

CVE-2026-58214 · Severity: medium · CVSS 4.3 · Published 2026-07-08

Technologies: Nats-Io NATS Server.

Executive brief

NATS Server is a high-performance messaging system used for cloud and edge computing. A security flaw allowed authenticated users to bypass their assigned permissions and access internal message metadata. This could lead to the exposure of sensitive protocol information belonging to other sessions within the same account.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in NATS Server's MQTT implementation. Authenticated MQTT clients can subscribe to the internal '$MQTT.deliver.pubrel' subject family, which should be restricted. This bypasses configured subscription ACLs and allows an attacker to view MQTT Quality of Service 2 (QoS2) protocol metadata for other sessions within the same account. The issue stems from a failure to block subscriptions to this specific internal prefix in the 'processSubs' function within 'server/mqtt.go'. The vulnerability is fixed in versions 2.12.12 and 2.14.3 by explicitly rejecting subscription requests for the affected internal subject prefix.

Affected products

  • nats-io nats-server < 2.12.12, >= 2.14.0-RC.1, < 2.14.3

Timeline

  • 2026-06-29: patched: Versions 2.12.12 and 2.14.3 released
  • 2026-07-08: disclosed: CVE-2026-58214 published

References