CVE-2026-33216Disclosure(linuxfoundation / nats-server)

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch linuxfoundation nats-server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, for MQTT deployments using usercodes/passwords: MQTT passwords are incorrectly classified as a non-authenticating identity statement (JWT) and exposed via monitoring endpoints. Versions 2.11.14 and 2.12.6 contain a fix. As a workaround, ensure monitoring end-points are adequately secured. Best practice remains to not expose the monitoring endpoint to the Internet or other untrusted network users.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-256CWE-213

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nats-server

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Affected systems

Products
nats-server

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-25: 3Patch / Workaround · 2026-03-25: 1Technical Details · 2026-03-25: 203-25
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets4 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-33216 NATS-Server is a High-Performance server for http://NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, for MQTT deployments using userc… https://www.cve.org/CVERecord?id=CVE-2026-33216

    Post summary

    The text announces CVE‑2026‑33216 for NATS‑Server, noting that versions older than 2.11.15/2.12.6 are vulnerable, but it provides no PoC, exploit, patch details, or evidence of active exploitation.

    00010108
    56.8K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33216: HIGH] Ensure NATS-Server is updated to versions 2.11.15 or 2.12.6 to fix MQTT password exposure issue. Secure monitoring endpoints or avoid exposing them to untrusted networks.#cve,CVE-2026-33216,#cybersecurity https://cvefind.com/CVE-2026-33216

    Post summary

    A vendor advisory urges updating NATS‑Server to specific patched versions to mitigate CVE‑2026‑33216, which involves MQTT password exposure; no proof of exploitation or PoC is referenced.

    0000033
    605 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-33216 - High NATS-Server is a High-Performance server for http://NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, for MQTT deployments using usercodes/passwords: MQTT pass... https://www.thehackerwire.com/vulnerability/CVE-2026-33216/ https://t.co/lIsvZqTwSN

    Post summary

    The tweet announces CVE‑2026‑33216 as a high‑severity flaw impacting NATS‑Server MQTT authentication in versions before 2.11.15 and 2.12.6, but it does not provide a proof‑of‑concept, exploit code, or patch details.

    0000039
    145 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxfoundationnats-server---

Explore more