Authentication Bypass Vulnerability in NATS-Server by NATS.io
CVE-2026-33216
8.6HIGH
What is CVE-2026-33216?
NATS-Server, a high-performance messaging system, has a vulnerability that allows for the incorrect handling of MQTT passwords. In versions earlier than 2.11.15 and 2.12.6, these passwords were misclassified as non-authenticating identity statements and could be exposed through monitoring endpoints. To mitigate this risk, users are advised to secure monitoring endpoints effectively and avoid exposing them to untrusted networks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
nats-server < 2.11.15 < 2.11.15
nats-server >= 2.12.0-RC.1, < 2.12.6 < 2.12.0-RC.1, 2.12.6
