PT-2026-27613 · Nats.Io · Nats Server

Published

2026-03-24

·

Updated

2026-05-21

·

CVE-2026-33216

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions NATS-Server versions prior to 2.11.15 NATS-Server versions prior to 2.12.6
Description NATS-Server, a high-performance server for NATS.io, a cloud and edge native messaging system, contains an issue where MQTT passwords are incorrectly classified as a non-authenticating identity statement (JWT) and exposed via monitoring endpoints in MQTT deployments using usercodes and passwords. As a result, sensitive password information may be accessible through these endpoints. It is recommended to adequately secure monitoring endpoints and avoid exposing them to untrusted networks.
Recommendations Update NATS-Server to version 2.11.15 or later. Update NATS-Server to version 2.12.6 or later. Ensure monitoring endpoints are adequately secured. Avoid exposing the monitoring endpoint to the Internet or other untrusted network users.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BIT-NATS-2026-33216
CVE-2026-33216
GHSA-V722-JCV5-W7MC
GO-2026-4836
SUSE-SU-2026:1135-1

Affected Products

Nats Server