NATS-Server Vulnerability in JetStream Admin API Permissions
CVE-2026-33222

4.9MEDIUM

Key Information:

Vendor

Nats-io

Vendor
CVE Published:
25 March 2026

What is CVE-2026-33222?

NATS-Server, a high-performance cloud messaging system, presents a vulnerability allowing users with JetStream admin API access to restore one stream to unintended other stream names. This flaw undermines data security by allowing potential unauthorized data manipulation. Versions 2.11.15 and 2.12.6 have addressed this issue. As an immediate precaution, developers should consider removing restore permissions for users configured with limited access until the necessary updates are applied.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

nats-server < 2.11.15 < 2.11.15

nats-server >= 2.12.0-RC.1, < 2.12.6 < 2.12.0-RC.1, 2.12.6

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.