PT-2026-41527 · Emqx · Emqx

Cccaaa

·

Published

2026-05-17

·

Updated

2026-05-20

·

CVE-2026-8741

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions EMQX versions prior to 6.2.0
Description A race condition exists in the QoS 2 PUBLISH Packet Handler component within the apps/emqx/src/emqx persistent session ds.erl file. This issue allows a remote attacker to trigger a race condition, which occurs when the system's substantive behavior is dependent on the sequence or timing of other uncontrollable events. This attack is characterized by high complexity and is difficult to exploit.
Recommendations Update to a version later than 6.2.0. As a temporary workaround, restrict access to the QoS 2 PUBLISH Packet Handler component to minimize the risk of exploitation.

Exploit

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8741

Affected Products

Emqx