← Späť na vyhľadávanie CVE

CVE-2026-44725

EMQX

Popis

EMQX is a scalable and reliable MQTT broker for AI, IoT, IIoT, and connected vehicles. Prior to versions 5.8.11, 5.9.3, 5.10.4, 6.0.3, 6.1.2, and 6.2.1, the plugin-install REST API and dashboard upload accepted stale grants created with emqx ctl plugins allow because there was no five-minute grant lifetime or SHA-256 package binding. An attacker with a compromised dashboard administrator credential or API key with plugin-install permission who finds a stale allowed name and version can upload attacker-controlled bytes under the allowed .tar.gz filename through POST /api/v5/plugins/install or the dashboard plugin upload. The broker then installs and runs attacker-controlled Erlang code with the privileges of the EMQX process. This issue is fixed in versions 5.8.11, 5.9.3, 5.10.4, 6.0.3, 6.1.2, and 6.2.1.

CVSS 6.6EPSS 0.253%Riziko 0.68
Zobraziť zdroj
Zverejnené
2026-08-20 15:17:30
Dotknuté verzie
<5.8.11, <5.9.3, <5.10.4, <6.0.3, <6.1.2, <6.2.1
Typ
Knižnica
Posledná úprava
2026-08-21 22:16:37
Vektor
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H