National Cyber Warfare Foundation (NCWF)

CVE-2026-33356


0 user ratings
2026-03-19 00:00:00
milo
CVEs

 - archive -- 

CVE-2026-33356

Date: 2026-03-19

CVE Link

In Meari IoT Cloud MQTT Broker deployments running EMQX 4.x, any authenticated low-privilege account can subscribe to global wildcard topics and receive telemetry from devices the user does not own. The broker enforces publish restrictions but does not enforce equivalent subscribe authorization at per-device scope.



References:



Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
CVEs



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.