top of page
perceptive_background_267k.jpg

An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creation of a new configuration entry in the system configuration. …

Published:

30 July 2026 at 00:00:00

Alert date:

30 July 2026 at 10:03:15

Source:

nvd.nist.gov

Click to open the original link from this advisory

Network Infrastructure, Mobile & IoT, Critical Infrastructure

CVE-2026-44091 describes a vulnerability where an unauthenticated remote attacker can post a malicious ID to an MQTT Broker, resulting in the creation of a new configuration entry in the system configuration. This attack requires no authentication, making it trivially exploitable by remote attackers. The vulnerability can lead to both integrity and availability loss of the affected system. It affects systems utilizing MQTT Broker functionality. The issue has been reported via NVD and CERT VDE advisory VDE-2026-008. The ability to inject configuration entries could allow persistent manipulation of system behavior. No authentication barrier exists to prevent exploitation, increasing the attack surface significantly.

Technical details

Mitigation steps:

Affected products:

MQTT Broker

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page