PT-2026-27617 · Nats.Io · Nats Server

CVE-2026-33222

·

Publicado

2026-03-24

·

Atualizado

2026-06-18

CVSS v3.1

4.9

Média

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions NATS-Server versions prior to 2.11.15 NATS-Server versions prior to 2.12.6
Description NATS-Server, a high-performance server for NATS.io, contains an issue where users with JetStream admin API access to restore one stream could restore to other stream names. This could impact data that should have been protected from unauthorized access. The JetStream management API, which includes backup and restore functionality, is affected.
Recommendations Update to version 2.11.15 or later. Update to version 2.12.6 or later. If limited JetStream restore permissions are configured for users, temporarily remove those permissions.

Exploit

Correção

Improper Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-NATS-2026-33222
CVE-2026-33222
GHSA-9983-VRX2-FG9C
GO-2026-4832
SUSE-SU-2026:1135-1

Produtos afetados

Nats Server