Security Vulnerability in EMQX MQTT Broker Affecting Multiple Versions
CVE-2026-44725
6.6MEDIUM
What is CVE-2026-44725?
The EMQX MQTT broker was found to be vulnerable to an improper input validation issue affecting its plugin-install REST API and dashboard upload features. This vulnerability allows an attacker with access to compromised dashboard administrator credentials or API keys to exploit stale grants, potentially leading to the execution of malicious Erlang code with the privileges of the EMQX process. This critical flaw has been addressed in subsequent releases, including versions 5.8.11, 5.9.3, 5.10.4, 6.0.3, 6.1.2, and 6.2.1, which enforce stricter security measures.
Affected Version(s)
emqx < 5.8.11 < 5.8.11
emqx >= 5.9.0, < 5.9.3 < 5.9.0, 5.9.3
emqx >= 5.10.0, < 5.10.4 < 5.10.0, 5.10.4
