Potential Bypass of ACLs in NATS-Server by MQTT Clients
CVE-2026-33217
7.1HIGH
What is CVE-2026-33217?
NATS-Server, a high-performance messaging system for cloud and edge environments, faced a significant vulnerability in its ACL implementation. Specifically, prior to versions 2.11.15 and 2.12.6, Access Control Lists (ACLs) applied to message subjects were not enforced within the $MQTT.> namespace, enabling MQTT clients to bypass essential ACL checks. This oversight could result in unauthorized message access. The affected versions have been updated to address this critical issue, and no known workarounds exist for users relying on the compromised functionality.
Affected Version(s)
nats-server < 2.11.15 < 2.11.15
nats-server >= 2.12.0-RC.1, < 2.12.6 < 2.12.0-RC.1, 2.12.6
