PT-2026-39640 · Emqx · Emqx
Sammy Azdoufal
+1
·
Published
2026-05-11
·
Updated
2026-05-11
·
CVE-2026-33356
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
EMQX versions 4.x
Description
In Meari IoT Cloud MQTT Broker deployments, an authenticated low-privilege account can subscribe to global wildcard topics, such as
meari/#, allowing the user to receive telemetry from devices they do not own. While the broker enforces publish Access Control Lists (ACLs), it fails to enforce equivalent subscribe authorization at the per-device scope. In a real-world test on a single broker, this allowed the capture of 14,204 messages from 2,117 devices.Recommendations
Update EMQX versions 4.x to a version where subscribe authorization is properly enforced at the per-device scope.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Emqx