CVE-2026-58214: NATS Server: MQTT subscribe ACL bypass via $MQTT.deliver.pubrel prefix (incomplete fix for CVE-2026-33217)
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, an authenticated MQTT client could subscribe to the internal $MQTT.deliver.pubrel subject family, bypassing configured subscribe permissions and exposing MQTT QoS2 protocol metadata for sessions in the account. This issue is fixed in versions 2.14.3 and 2.12.12.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
nats-serverto a version that resolves this vulnerability.Fixed in 2.14.3 - Upgrade
Upgrade
nats-serverto a version that resolves this vulnerability.Fixed in 2.12.12
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58214?
The severity of CVE-2026-58214 is classified as medium with a score of 4.3.
How do I fix CVE-2026-58214?
To fix CVE-2026-58214, upgrade to NATS Server version 2.14.3 or 2.12.12 or later.
What type of vulnerability is CVE-2026-58214?
CVE-2026-58214 is an access control vulnerability that allows an authenticated MQTT client to bypass configured subscribe permissions.
What software is affected by CVE-2026-58214?
CVE-2026-58214 affects the NATS Server software, specifically versions prior to 2.14.3 and 2.12.12.
What is the impact of CVE-2026-58214?
The impact of CVE-2026-58214 includes exposure of the MQTT QoS2 protocol due to improper access controls.