
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33249 is an incorrect authorization vulnerability in NATS-Server (nats-io/nats-server) that allows an authenticated client to redirect message tracing output to arbitrary subjects without the required publish permissions. The vulnerability was published on March 24, 2026, and affects NATS-Server versions 2.11.0 through 2.11.14 and 2.12.0-preview.1 through 2.12.5. Fixed versions 2.11.15 and 2.12.6 were released simultaneously with disclosure. It carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, Red Hat Bugzilla).
The root cause is classified as CWE-863 (Incorrect Authorization) and CWE-1220 (Insufficient Granularity of Access Control). NATS-Server supports per-message telemetry via NATS message tracing headers; a valid, authenticated client can set a tracing header that instructs the server to deliver trace messages to an arbitrary subject — including subjects for which the client lacks publish permission. Critically, the payload delivered to the unauthorized subject is a valid, server-generated trace message and is not attacker-controlled content. Exploitation requires only low-privilege network access and no user interaction (GitHub Advisory, NATS Advisory).
Successful exploitation allows a low-privileged authenticated attacker to route trace messages to subjects they are not authorized to publish to, violating the server's access control model. The integrity impact is limited — the attacker cannot control the content of the trace message payload, only its destination subject. There is no confidentiality or availability impact, and the scope is unchanged, meaning the vulnerability does not enable lateral movement or data exfiltration beyond unauthorized message routing within the NATS messaging fabric (GitHub Advisory, Red Hat Bugzilla).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (GitHub Advisory). No threat actor attribution has been reported. The EPSS score is approximately 0.026% (2nd percentile), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection coverage exists via Nessus (ID 303845) and Qualys (IDs 761875, 6563643) (Feedly).
Nats-Trace-Dest) set to the target unauthorized subject./connz, /subsz).Nats-Trace-Dest) values in client connections pointing to sensitive or administrative subjects; clients sending messages with tracing headers to subjects outside their normal operational scope.Upgrade NATS-Server to version 2.11.15 or 2.12.6, which contain the fix for this vulnerability (GitHub Advisory, NATS Advisory). The vendor has confirmed there are no known workarounds available. As a defense-in-depth measure, restrict publish permissions carefully to limit which subjects authenticated users can access, and monitor message tracing activity for suspicious redirection patterns to unauthorized subjects (Red Hat Bugzilla).
The advisory was published by philpennock on the nats-io/nats-server GitHub repository on March 24, 2026, and was simultaneously cross-referenced with the canonical NATS security advisory at advisories.nats.io. Red Hat tracked the issue via Bugzilla (Bug 2451485) and classified it as medium severity. openSUSE issued a security announcement referencing the vulnerability, and it was picked up by Linux security aggregators shortly after disclosure (openSUSE, Red Hat Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."