top of page
perceptive_background_267k.jpg

An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creation of a new configuration entry in the system configuration. …

Published:

30 juli 2026 om 00:00:00

Alert date:

30 juli 2026 om 10:03:15

Source:

nvd.nist.gov

Click to open the original link from this advisory

Network Infrastructure, Mobile & IoT, Critical Infrastructure

CVE-2026-44091 describes a vulnerability where an unauthenticated remote attacker can post a malicious ID to an MQTT Broker, resulting in the creation of a new configuration entry in the system configuration. This attack requires no authentication, making it trivially exploitable by remote attackers. The vulnerability can lead to both integrity and availability loss of the affected system. It affects systems utilizing MQTT Broker functionality. The issue has been reported via NVD and CERT VDE advisory VDE-2026-008. The ability to inject configuration entries could allow persistent manipulation of system behavior. No authentication barrier exists to prevent exploitation, increasing the attack surface significantly.

Technical details

Mitigation steps:

Affected products:

MQTT Broker

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page