Race Condition in EMQX QoS 2 PUBLISH Packet Handler
CVE-2026-8741
Key Information:
Badges
What is CVE-2026-8741?
A vulnerability exists within the EMQX Broker that affects the QoS 2 PUBLISH packet handler, specifically in the function located at apps/emqx/src/emqx_persistent_session_ds.erl. This flaw can be exploited remotely, leading to a race condition which may complicate the management of message sessions between distributed systems. Although the exploit's complexity is deemed high, it has been publicly disclosed, raising concerns for users of affected EMQX versions, including 6.1.0 and 6.2.0. Users are advised to closely monitor this issue and implement appropriate security measures.
Affected Version(s)
EMQX 6.0
EMQX 6.1
EMQX 6.2.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
