SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-44091

CRITICAL · CVSS 9.1 EPSS 0.36%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

An unauthenticated remote attacker can exploit a vulnerability in the MQTT Broker to post a malicious ID, resulting in the creation of unauthorized configuration entries. This could compromise the integrity and availability of the system, making it critical for organizations using MQTT Broker to prioritize mitigation efforts. Immediate action is essential to prevent potential exploitation and safeguard system operations.

CVE
CVE-2026-44091
Severity
CRITICAL
CVSS
9.1
EPSS
0.36%

Original NVD Description

An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creation of a new configuration entry in the system configuration. This may lead to integrity and availability loss.