Home

Description

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using ACLs on message subjects, these ACLs were not applied in the `$MQTT.>` namespace, allowing MQTT clients to bypass ACL checks for MQTT subjects. Versions 2.11.15 and 2.12.6 contain a fix. No known workarounds are available.

PUBLISHED Reserved 2026-03-17 | Published 2026-03-25 | Updated 2026-03-25 | Assigner GitHub_M




HIGH: 7.1CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N

Problem types

CWE-863: Incorrect Authorization

Product status

< 2.11.15
affected

>= 2.12.0-RC.1, < 2.12.6
affected

References

github.com/...server/security/advisories/GHSA-jxxm-27vp-c3m5

advisories.nats.io/CVE/secnote-2026-07.txt

cve.org (CVE-2026-33217)

nvd.nist.gov (CVE-2026-33217)

Download JSON