PT-2026-39640 · Emqx · Emqx

Sammy Azdoufal

+1

·

Published

2026-05-11

·

Updated

2026-05-11

·

CVE-2026-33356

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions EMQX versions 4.x
Description In Meari IoT Cloud MQTT Broker deployments, an authenticated low-privilege account can subscribe to global wildcard topics, such as meari/#, allowing the user to receive telemetry from devices they do not own. While the broker enforces publish Access Control Lists (ACLs), it fails to enforce equivalent subscribe authorization at the per-device scope. In a real-world test on a single broker, this allowed the capture of 14,204 messages from 2,117 devices.
Recommendations Update EMQX versions 4.x to a version where subscribe authorization is properly enforced at the per-device scope.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-33356

Affected Products

Emqx