216.73.216.226

CVE-2026-33356

· Published 11/05/2026 17:16 · Modified 11/05/2026 17:16

Labels: CVE-2026-33356 2026-05-1144488dab-36db-4358-99f9-bc116477f914CVE-2026-33356CWE-639

Essential information

Published
11/05/2026 17:16
Modified
11/05/2026 17:16
Author
Creator
CVSS
7.7 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

CVSS metrics

Description

In Meari IoT Cloud MQTT Broker deployments running EMQX 4.x, any authenticated low-privilege account can subscribe to global wildcard topics and receive telemetry from devices the user does not own. The broker enforces publish restrictions but does not enforce equivalent subscribe authorization at per-device scope.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
44488dab-36db-4358-99f9-bc116477f914
NVD
View on NVD

Affected products (CPE)

ProductCPE
meari / emq cpe:2.3:a:meari:emq:4.*:*:*:*:*:*:*:*

References