CVE-2026-33356
HIGH SEVERITYCVSS Score & Metrics
Base Score
7.7 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Vulnerability Description
In Meari IoT Cloud MQTT Broker deployments running EMQX 4.x, any authenticated low-privilege account can subscribe to global wildcard topics and receive telemetry from devices the user does not own. The broker enforces publish restrictions but does not enforce equivalent subscribe authorization at per-device scope.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-639
Source
NVD
Vendor
Meari
Product
IoT Cloud MQTT Broker EMQX
Discussion (0)
Add Comment
No comments yet. Be the first!