NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server provides an MQTT client interface. Prior to versions 2.11.15 and 2.12.5, Sessions and Messages can by hijacked via MQTT Client ID malfeasance. Versions 2.11.15 and 2.12.5 patch the issue. No known workarounds are available.
Metrics
Affected Vendors & Products
References
History
Tue, 24 Mar 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server provides an MQTT client interface. Prior to versions 2.11.15 and 2.12.5, Sessions and Messages can by hijacked via MQTT Client ID malfeasance. Versions 2.11.15 and 2.12.5 patch the issue. No known workarounds are available. | |
| Title | NATS is vulnerable to MQTT hijacking via Client ID | |
| Weaknesses | CWE-287 CWE-488 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-24T20:55:53.455Z
Reserved: 2026-03-17T23:23:58.314Z
Link: CVE-2026-33215
No data.
Status : Received
Published: 2026-03-24T21:16:28.640
Modified: 2026-03-24T21:16:28.640
Link: CVE-2026-33215
No data.
OpenCVE Enrichment
No data.