
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33222 is an authorization bypass vulnerability in NATS-Server's JetStream Management API, titled "JetStream: Stream restore endpoint auth bypass." It affects all versions of github.com/nats-io/nats-server/v2 prior to 2.11.15 and prior to 2.12.6 (including the 2.12.0-RC.1 through 2.12.5 range). The vulnerability was published on March 24, 2026, and assigned a CVSS v3.1 base score of 4.9 (Medium) (GitHub Advisory, Red Hat Bugzilla).
The root cause is improper authorization (CWE-285) combined with authorization bypass through user-controlled key (CWE-639) in the JetStream stream restore endpoint. When a user is granted JetStream admin API access scoped to restoring a specific stream, the server fails to enforce that the restore operation targets only the permitted stream name — allowing the user to supply an arbitrary stream name as a user-controlled parameter and restore data to streams they should not have access to. Exploitation requires network access and a high-privilege account (JetStream admin API credentials), but no user interaction or complex conditions are needed (GitHub Advisory, NATS Advisory).
Successful exploitation allows an authenticated attacker with limited JetStream restore permissions to overwrite or corrupt data in streams beyond their authorized scope, resulting in a high integrity impact. There is no confidentiality or availability impact per the CVSS assessment, meaning the attacker cannot directly read protected stream data but can tamper with it. In environments where stream data isolation is a security boundary (e.g., multi-tenant deployments), this could lead to unauthorized data modification affecting other tenants or services (GitHub Advisory, Red Hat Bugzilla).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of writing. The EPSS score is approximately 0.009% (1st percentile), indicating a very low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is limited to users who already hold JetStream admin API credentials, significantly constraining the attacker pool (GitHub Advisory).
nats CLI) authenticated with the obtained credentials.$JS.API.STREAM.RESTORE.*) initiated by a user account targeting stream names outside their expected permission scope.Upgrade NATS-Server to version 2.11.15 or 2.12.6, which contain the fix for this vulnerability. As an immediate workaround for deployments that cannot upgrade promptly, administrators should temporarily revoke JetStream restore permissions from any users who have been granted limited/scoped restore access, until the patch can be applied. Organizations not using scoped JetStream restore permissions are not exposed to this specific bypass (GitHub Advisory, NATS Advisory).
The vulnerability was published by philpennock to the nats-io/nats-server GitHub repository on March 24, 2026, and reviewed the same day. Red Hat tracked it via Bugzilla (Bug 2451480) and OpenSUSE issued a security announcement referencing the issue. No significant broader media coverage or notable researcher commentary beyond the official advisory has been identified (Red Hat Bugzilla, GitHub Advisory).
Fix availability across major Linux distributions and their releases.
devel
nats-server
noble
nats-server
noble (esm-apps)
nats-server
resolute
nats-server
resolute (esm-apps)
nats-server
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."