PT-2026-27613 · Nats.Io · Nats Server
Published
2026-03-24
·
Updated
2026-05-21
·
CVE-2026-33216
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
NATS-Server versions prior to 2.11.15
NATS-Server versions prior to 2.12.6
Description
NATS-Server, a high-performance server for NATS.io, a cloud and edge native messaging system, contains an issue where MQTT passwords are incorrectly classified as a non-authenticating identity statement (JWT) and exposed via monitoring endpoints in MQTT deployments using usercodes and passwords. As a result, sensitive password information may be accessible through these endpoints. It is recommended to adequately secure monitoring endpoints and avoid exposing them to untrusted networks.
Recommendations
Update NATS-Server to version 2.11.15 or later.
Update NATS-Server to version 2.12.6 or later.
Ensure monitoring endpoints are adequately secured.
Avoid exposing the monitoring endpoint to the Internet or other untrusted network users.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nats Server