Authentication Bypass in MQTT Broker Exposing Devices to Remote Attacks
CVE-2026-44090

9.3CRITICAL

Key Information:

Vendor
CVE Published:
30 July 2026

What is CVE-2026-44090?

The MQTT Broker is susceptible to an authentication bypass due to inadequate access controls. An unauthenticated remote attacker can exploit this vulnerability to gain unauthorized access to the broker, which is primarily secured by a firewall. This exposure can lead to the complete compromise of devices connected to the broker, enabling attackers to manipulate or steal sensitive data.

Affected Version(s)

CHARX SEC-3000 1.0.0 < 1.9.1

CHARX SEC-3050 1.0.0 < 1.9.1

CHARX SEC-3100 1.0.0 < 1.9.1

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ZDI
.