NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing.
The nats-server provides an MQTT client interface.
When using ACLs on message subjects, these ACLs were not applied in the $MQTT.> namespace, allowing MQTT clients to bypass ACL checks for MQTT subjects.
Any version before v2.12.6 or v2.11.15
None.
{
"nvd_published_at": "2026-03-25T20:16:32Z",
"github_reviewed_at": "2026-03-24T21:44:17Z",
"cwe_ids": [
"CWE-863"
],
"severity": "HIGH",
"github_reviewed": true
}