In Meari IoT Cloud MQTT Broker deployments running EMQX 4.x, any authenticated low-privilege account can subscribe to global wildcard topics and receive telemetry from devices the user does not own. The broker enforces publish restrictions but does not enforce equivalent subscribe authorization at per-device scope.
Metrics
Affected Vendors & Products
References
History
Tue, 12 May 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Meari
Meari iot Cloud Mqtt Broker Emqx |
|
| Vendors & Products |
Meari
Meari iot Cloud Mqtt Broker Emqx |
Mon, 11 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 11 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Meari IoT Cloud MQTT Broker deployments running EMQX 4.x, any authenticated low-privilege account can subscribe to global wildcard topics and receive telemetry from devices the user does not own. The broker enforces publish restrictions but does not enforce equivalent subscribe authorization at per-device scope. | |
| Title | Meari MQTT broker missing per-device subscribe ACL | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: runZero
Published:
Updated: 2026-05-11T18:18:45.410Z
Reserved: 2026-03-19T00:27:05.986Z
Link: CVE-2026-33356
Updated: 2026-05-11T18:18:42.323Z
Status : Received
Published: 2026-05-11T17:16:30.590
Modified: 2026-05-11T17:16:30.590
Link: CVE-2026-33356
No data.