


Perceptive Security
SOC/SIEM Consultancy

Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected from external access by a firewall. This m…
Published:
30 July 2026 at 00:00:00
Alert date:
30 July 2026 at 17:06:27
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure, Critical Infrastructure, Identity & Access
CVE-2026-44090 describes a critical vulnerability where an MQTT broker lacks proper authentication, allowing unauthenticated remote attackers to gain access. The broker is only protected by a firewall, which is insufficient as a sole security control. Exploitation of this vulnerability could result in full device compromise. The issue stems from a missing authentication mechanism on the MQTT service. MQTT brokers are commonly used in IoT and industrial environments, making this a significant risk. The vulnerability was reported via CERT VDE advisory VDE-2026-008. No credentials are required for exploitation, lowering the barrier for attackers. Network-adjacent or internet-exposed devices are at heightened risk if firewall rules are insufficient or misconfigured.
Technical details
Mitigation steps:
Affected products:
MQTT Broker
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
