PT-2026-27613 · Nats.Io · Nats Server

·

CVE-2026-33216

·

Publicado

2026-03-24

·

Atualizado

2026-08-24

CVSS v3.1

8.6

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions NATS-Server versions prior to 2.11.15 NATS-Server versions prior to 2.12.6
Description NATS-Server, a high-performance server for NATS.io, a cloud and edge native messaging system, contains an issue where MQTT passwords are incorrectly classified as a non-authenticating identity statement (JWT) and exposed via monitoring endpoints in MQTT deployments using usercodes and passwords. As a result, sensitive password information may be accessible through these endpoints. It is recommended to adequately secure monitoring endpoints and avoid exposing them to untrusted networks.
Recommendations Update NATS-Server to version 2.11.15 or later. Update NATS-Server to version 2.12.6 or later. Ensure monitoring endpoints are adequately secured. Avoid exposing the monitoring endpoint to the Internet or other untrusted network users.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

AZL-81636
BIT-NATS-2026-33216
CVE-2026-33216
GHSA-V722-JCV5-W7MC
GO-2026-4836
JLSEC-2026-1124
OPENSUSE-SU-2026:21483-1
SUSE-SU-2026:1135-1

Produtos afetados

Nats Server