NATS-Server Vulnerability in JetStream Admin API Permissions
CVE-2026-33222
4.9MEDIUM
What is CVE-2026-33222?
NATS-Server, a high-performance cloud messaging system, presents a vulnerability allowing users with JetStream admin API access to restore one stream to unintended other stream names. This flaw undermines data security by allowing potential unauthorized data manipulation. Versions 2.11.15 and 2.12.6 have addressed this issue. As an immediate precaution, developers should consider removing restore permissions for users configured with limited access until the necessary updates are applied.
Affected Version(s)
nats-server < 2.11.15 < 2.11.15
nats-server >= 2.12.0-RC.1, < 2.12.6 < 2.12.0-RC.1, 2.12.6
