CVE-2026-8741
נמוכה 3.1
תיאור (מקור, אנגלית)
A vulnerability has been found in EMQX up to 6.2.0. This affects an unknown function of the file apps/emqx/src/emqx_persistent_session_ds.erl of the component QoS 2 PUBLISH Packet Handler. Such manipulation leads to race condition. The attack may be performed from remote. A high complexity level is associated with this attack. The exploitability is reported as difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure.
מדדים
- CVSS 3.1
-
3.1 (LOW)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L - CVSS 4.0
-
1.3 (LOW)
מקור הציון: CNA
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-4/8/2026
- CWE
- CWE-362
מוצרים מושפעים
emqx: emqx
קישורים
- https://github.com/Pathfind-tama/Report_EMQX_MQTT/blob/main/MQTT%20QoS%202%20M… ExploitMitigationThird Party Advisory
- https://github.com/Pathfind-tama/Report_EMQX_MQTT Third Party Advisory
- https://vuldb.com/submit/809931 Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/364329 Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/364329/cti Permissions RequiredVDB Entry