CVE-2026-6564Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in EMQ EMQX Enterprise up to 6.1.0. The impacted element is an unknown function of the component Session Handling. The manipulation results in improper authorization. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-266CWE-285

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-19: 3Technical Details · 2026-04-19: 104-19
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-6564 Improper Authorization in EMQ EMQX Enterprise Session Handling Up to 6.1.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6564

    Post summary

    This brief entry notes an improper authorization flaw in EMQX Enterprise session handling up to version 6.1.0, but provides no PoC, exploit, patch, or active exploitation details.

    0000051
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-6564 A vulnerability was found in EMQ EMQX Enterprise up to 6.1.0. The impacted element is an unknown function of the component Session Handling. The manipulation results in… https://www.cve.org/CVERecord?id=CVE-2026-6564 ----- Traducción: CVE-2026-6564 Se … http://infoflow.cloud`

    Post summary

    The text announces the disclosure of CVE-2026-6564 for EMQ EMQX Enterprise with minimal technical detail, lacking evidence of exploitation, patches, or PoC availability.

    0000038
    72 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6564 A vulnerability was found in EMQ EMQX Enterprise up to 6.1.0. The impacted element is an unknown function of the component Session Handling. The manipulation results in… https://www.cve.org/CVERecord?id=CVE-2026-6564

    Post summary

    A vulnerability affecting EMQ X Enterprise up to version 6.1.0 (Session Handling) has been identified, but no exploit code, patch, or evidence of active exploitation is provided.

    00000182
    57.2K followersView on X

Explore more