Security Vulnerability in EMQX MQTT Broker Affecting Multiple Versions
CVE-2026-44725

6.6MEDIUM

Key Information:

Vendor

EMQx

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-44725?

The EMQX MQTT broker was found to be vulnerable to an improper input validation issue affecting its plugin-install REST API and dashboard upload features. This vulnerability allows an attacker with access to compromised dashboard administrator credentials or API keys to exploit stale grants, potentially leading to the execution of malicious Erlang code with the privileges of the EMQX process. This critical flaw has been addressed in subsequent releases, including versions 5.8.11, 5.9.3, 5.10.4, 6.0.3, 6.1.2, and 6.2.1, which enforce stricter security measures.

Affected Version(s)

emqx < 5.8.11 < 5.8.11

emqx >= 5.9.0, < 5.9.3 < 5.9.0, 5.9.3

emqx >= 5.10.0, < 5.10.4 < 5.10.0, 5.10.4

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.