PT-2026-27613 · Nats.Io · Nats Server

·

CVE-2026-33216

·

Published

2026-03-24

·

Updated

2026-08-24

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions NATS-Server versions prior to 2.11.15 NATS-Server versions prior to 2.12.6
Description NATS-Server, a high-performance server for NATS.io, a cloud and edge native messaging system, contains an issue where MQTT passwords are incorrectly classified as a non-authenticating identity statement (JWT) and exposed via monitoring endpoints in MQTT deployments using usercodes and passwords. As a result, sensitive password information may be accessible through these endpoints. It is recommended to adequately secure monitoring endpoints and avoid exposing them to untrusted networks.
Recommendations Update NATS-Server to version 2.11.15 or later. Update NATS-Server to version 2.12.6 or later. Ensure monitoring endpoints are adequately secured. Avoid exposing the monitoring endpoint to the Internet or other untrusted network users.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-81636
BIT-NATS-2026-33216
CVE-2026-33216
GHSA-V722-JCV5-W7MC
GO-2026-4836
JLSEC-2026-1124
OPENSUSE-SU-2026:21483-1
SUSE-SU-2026:1135-1

Affected Products

Nats Server