SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-58209

MEDIUM · CVSS 4.3 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

The vulnerability affects NATS Server versions prior to 2.14.3 and 2.12.12, where MQTT retained message delivery and QoS1+ durable replay could bypass subscriber deny rules, allowing unauthorized message delivery. This could lead to sensitive information being exposed to unintended recipients, posing a risk to data confidentiality. Organizations using affected versions of NATS Server, particularly those handling sensitive messaging, should prioritize upgrading to the patched versions to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-58209
Severity
MEDIUM
CVSS
4.3
EPSS
0.25%

Original NVD Description

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, MQTT retained message delivery and QoS1+ durable replay could deliver messages whose original topics matched a subscriber configured subscribe deny rule because these delivery paths did not consistently recheck the concrete original topic before sending the MQTT PUBLISH to the subscriber. This issue is fixed in versions 2.14.3 and 2.12.12.

Related CVEs

Other vulnerabilities affecting the same vendor(s)