PT-2026-47797 · Emqx · Emqx

CVE-2026-44725

·

Published

2026-06-09

·

Updated

2026-08-21

CVSS v3.1

6.6

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EMQX versions prior to 5.8.11 EMQX versions prior to 5.9.3 EMQX versions prior to 5.10.4 EMQX versions prior to 6.0.3 EMQX versions prior to 6.1.2 EMQX versions prior to 6.2.1
Description The plugin-install REST API and dashboard upload mechanism accept stale grants created with emqx ctl plugins allow due to the absence of a five-minute grant lifetime or SHA-256 package binding. An attacker possessing compromised dashboard administrator credentials or an API key with plugin-install permissions can exploit a stale allowed name and version to upload malicious bytes via a .tar.gz file. This is achieved through the POST /api/v5/plugins/install endpoint or the dashboard plugin upload. Consequently, the broker installs and executes attacker-controlled Erlang code with the privileges of the EMQX process, leading to remote code execution and arbitrary file write on the system via a Zip Slip mechanism.
Recommendations Update to version 5.8.11 Update to version 5.9.3 Update to version 5.10.4 Update to version 6.0.3 Update to version 6.1.2 Update to version 6.2.1

Exploit

Fix

RCE

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44725
GHSA-CP9X-5QWC-FJ6R

Affected Products

Emqx