{"apiVersion":"1.0","identifier":"CVE-2026-44725","description":"EMQX is a scalable and reliable MQTT broker for AI, IoT, IIoT, and connected vehicles. Prior to versions 5.8.11, 5.9.3, 5.10.4, 6.0.3, 6.1.2, and 6.2.1, the plugin-install REST API and dashboard upload accepted stale grants created with emqx ctl plugins allow because there was no five-minute grant lifetime or SHA-256 package binding. An attacker with a compromised dashboard administrator credential or API key with plugin-install permission who finds a stale allowed name and version can upload attacker-controlled bytes under the allowed .tar.gz filename through POST /api/v5/plugins/install or the dashboard plugin upload. The broker then installs and runs attacker-controlled Erlang code with the privileges of the EMQX process. This issue is fixed in versions 5.8.11, 5.9.3, 5.10.4, 6.0.3, 6.1.2, and 6.2.1.","publishedAt":"2026-08-20T15:17:30","lastModifiedAt":"2026-08-21T22:16:37","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-44725","cvssScore":6.6,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","epssProbability":0.00253,"riskScore":0.68,"affectedProduct":"EMQX","affectedVersions":"<5.8.11, <5.9.3, <5.10.4, <6.0.3, <6.1.2, <6.2.1","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-44725","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-44725","en":"https://www.redsauce.net/en/cves/CVE-2026-44725","fr":"https://www.redsauce.net/fr/cves/CVE-2026-44725","pt":"https://www.redsauce.net/pt/cves/CVE-2026-44725","de":"https://www.redsauce.net/de/cves/CVE-2026-44725","sk":"https://www.redsauce.net/sk/cves/CVE-2026-44725","el":"https://www.redsauce.net/el/cves/CVE-2026-44725"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-44725"}}