CVE-2026-33215: NATS is vulnerable to MQTT hijacking via Client ID
Background
NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing.
The nats-server provides an MQTT client interface.
Problem Description
Sessions and Messages can by hijacked via MQTT Client ID malfeasance.
Affected Versions
Any version before v2.12.6 or v2.11.15
Workarounds
None.
Resources
This document is canonically: <https://advisories.nats.io/CVE/secnote-2026-06.txt> GHSA advisory: <https://github.com/nats-io/nats-server/security/advisories/GHSA-fcjp-h8cc-6879> MITRE CVE entry: <https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33215>
Other sources
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server provides an MQTT client interface. Prior to versions 2.11.15 and 2.12.5, Sessions and Messages can by hijacked via MQTT Client ID malfeasance. Versions 2.11.15 and 2.12.5 patch the issue. No known workarounds are available.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33215?
The severity of CVE-2026-33215 is classified as high due to the potential for MQTT hijacking.
How do I fix CVE-2026-33215?
To fix CVE-2026-33215, upgrade NATS Server to version 2.12.6 or later, or 2.11.15.
What systems are affected by CVE-2026-33215?
CVE-2026-33215 affects NATS Server versions up to 2.11.15 and 2.12.5.
What impact does CVE-2026-33215 have on NATS performance?
CVE-2026-33215 can compromise the integrity of MQTT sessions, leading to unauthorized access.
Is there a workaround for CVE-2026-33215?
There is no documented workaround for CVE-2026-33215, so upgrading is necessary.