CVE-2026-33216 impacts NATS-Server versions prior to 2.11.15 and 2.12.6, where MQTT passwords are improperly exposed via monitoring endpoints due to being misclassified as non-authenticating identity statements. This vulnerability has a CVSS score of 7.5 (High), indicating a high confidentiality impact as unauthenticated attackers can remotely access sensitive MQTT passwords with low attack complexity. While there is no known active exploitation or public exploit code available, the CVE is on the Hot List and has generated significant community discussion. Organizations should update to patched versions (2.11.15 or 2.12.6) or ensure monitoring endpoints are adequately secured and not exposed to untrusted networks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.11.15CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:nats-server:*:*:*:*:*:*:*:* | ||
>= 2.12.0, < 2.12.6CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:nats-server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.