Remote Code Execution Vulnerability in MQTT Broker by Vendor
CVE-2026-44091

8.8HIGH

Key Information:

Vendor
CVE Published:
30 July 2026

What is CVE-2026-44091?

An unauthenticated remote attacker can exploit a flaw in the MQTT Broker by posting a crafted malicious ID, which leads to the creation of unauthorized configuration entries. This vulnerability can compromise the integrity and availability of the system, potentially allowing attackers to manipulate configurations or disrupt service.

Affected Version(s)

CHARX SEC-3000 1.0.0 < 1.9.1

CHARX SEC-3050 1.0.0 < 1.9.1

CHARX SEC-3100 1.0.0 < 1.9.1

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ZDI
.