
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33215 is an MQTT session and message hijacking vulnerability in NATS-Server, a high-performance cloud and edge native messaging system. The flaw exists in the MQTT client interface and allows unauthenticated remote attackers to hijack sessions and messages via MQTT Client ID malfeasance. Affected versions include all nats-server releases before v2.11.15 and v2.12.0-RC.1 through v2.12.5 (i.e., before v2.12.6). It was published on March 24, 2026, with a CVSS v3.1 base score of 6.5 (Medium/Moderate) (Github Advisory, NATS Advisory).
The root cause is classified as CWE-287 (Improper Authentication) and CWE-488 (Exposure of Data Element to Wrong Session). The NATS-Server MQTT interface fails to adequately validate or authenticate MQTT Client IDs, allowing an attacker to craft or reuse a Client ID that matches an existing legitimate session. By connecting with a manipulated Client ID, an attacker can take over an active MQTT session and intercept or inject messages intended for the legitimate client. The attack requires no privileges and no user interaction, though it carries high attack complexity, suggesting some knowledge of existing Client IDs or session state is needed (Github Advisory, NATS Advisory).
Successful exploitation allows an unauthenticated network attacker to hijack MQTT client sessions and intercept messages, resulting in high confidentiality impact — sensitive data transmitted over MQTT can be exposed to unauthorized parties. There is also a low availability impact, as legitimate clients may be disconnected when their session is taken over. Integrity of MQTT communications is also at risk, as an attacker controlling a hijacked session could potentially inject or suppress messages within the affected session scope (Github Advisory, NATS Advisory).
As of the time of disclosure, there is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.017% (4th percentile), indicating a low near-term probability of exploitation. No threat actor attribution has been reported.
The NATS project has released patched versions 2.11.15 and 2.12.6 that address this vulnerability; organizations should upgrade immediately. There are no known configuration-based workarounds available. As interim risk reduction measures, administrators should restrict network access to the NATS-Server MQTT interface to trusted clients only, implement network segmentation to isolate MQTT services from untrusted networks, and monitor MQTT connection logs for suspicious Client ID patterns or anomalous session behavior (Github Advisory, NATS Advisory).
The advisory was published by NATS maintainer philpennock on March 24, 2026, and was picked up by multiple vulnerability tracking platforms including ENISA EUVD, VulDB, Tenable (Nessus plugin 303635), and openSUSE security announcements. A technical write-up was published by Infinit Security covering the MQTT hijacking mechanism. The vulnerability received moderate community attention given its relevance to IoT and cloud-native messaging deployments (NATS Advisory).
Fix availability across major Linux distributions and their releases.
devel
nats-server
noble
nats-server
noble (esm-apps)
nats-server
resolute
nats-server
resolute (esm-apps)
nats-server
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."