Race Condition in EMQX QoS 2 PUBLISH Packet Handler
CVE-2026-8741

2.3LOW

Key Information:

Vendor

EMQX

Status
Vendor
CVE Published:
17 May 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-8741?

A vulnerability exists within the EMQX Broker that affects the QoS 2 PUBLISH packet handler, specifically in the function located at apps/emqx/src/emqx_persistent_session_ds.erl. This flaw can be exploited remotely, leading to a race condition which may complicate the management of message sessions between distributed systems. Although the exploit's complexity is deemed high, it has been publicly disclosed, raising concerns for users of affected EMQX versions, including 6.1.0 and 6.2.0. Users are advised to closely monitor this issue and implement appropriate security measures.

Affected Version(s)

EMQX 6.0

EMQX 6.1

EMQX 6.2.0

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

CCCaaa (VulDB User)
VulDB CNA Team
.