Ad

CVE-2026-33249

MEDIUM CVSS 3.1: 4.3
Updated Mar 25, 2026
Payload
Parameter Value
CVSS 4.3 (MEDIUM)
Type CWE-863 (Incorrect Authorization)
Vendor Payload
Public PoC No

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.11.0 and prior to versions 2.11.15 and 2.12.6, a valid client which uses message tracing headers can indicate that the trace messages can be sent to an arbitrary valid subject, including those to which the client does not have publish permission. The payload is a valid trace message and not chosen by the attacker.

Versions 2.11.15 and 2.12.6 contain a fix. No known workarounds are available.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v3.1