โ† ุงู„ุนูˆุฏุฉ ู„ู„ุฌุฏูˆู„
CVE-2026-49186
CVE-2026-49186 โ€” The local MQTT broker does not enforce topic-level Access Control Lists (ACLs).
๐Ÿ“… 2026-06-04
๐Ÿ”ด Critical ๐Ÿ”ฅ No NVD Exploit Network CVSS 9.8 ๐ŸŽฏ EPSS 0.04%

๐Ÿ“‹ ุงู„ูˆุตู ุงู„ูƒุงู…ู„

The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (#ย orย +) to enumerate hidden network devices or publish rogue control commands.

๐Ÿ’ป ุงู„ุฃู†ุธู…ุฉ ุงู„ู…ุชุฃุซุฑุฉ

The local MQTT

โš ๏ธ ู†ูˆุน ุงู„ุชู‡ุฏูŠุฏ

Exploit

๐Ÿ”— CVE ID

CVE-2026-49186

๐Ÿ“ก ุงู„ู…ุตุฏุฑ

NVD

โœ… ุงู„ุญู„ูˆู„ ูˆุงู„ุชุฎููŠู

Refer to CVE-2026-49186 NVD advisory

๐Ÿ”— ุงู„ู…ุตุฏุฑ ุงู„ุฃุตู„ูŠ โ† ๐Ÿ“˜ NVD โ† โšก CISA KEV โ†