Vulnerability Details CVE-2026-33216
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, for MQTT deployments using usercodes/passwords: MQTT passwords are incorrectly classified as a non-authenticating identity statement (JWT) and exposed via monitoring endpoints. Versions 2.11.14 and 2.12.6 contain a fix. As a workaround, ensure monitoring end-points are adequately secured. Best practice remains to not expose the monitoring endpoint to the Internet or other untrusted network users.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 28.4%
CVSS Severity
CVSS v3 Score 8.6
Products affected by CVE-2026-33216
-
cpe:2.3:a:linuxfoundation:nats-server:2.12.0
-
cpe:2.3:a:linuxfoundation:nats-server:2.12.1
-
cpe:2.3:a:linuxfoundation:nats-server:2.12.2
-
cpe:2.3:a:linuxfoundation:nats-server:2.12.3
-
cpe:2.3:a:linuxfoundation:nats-server:2.12.4
-
cpe:2.3:a:linuxfoundation:nats-server:2.12.5