NVD Vulnerability Detail
Search Exploit, PoC
CVE-2026-49186
Summary

The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (# or +) to enumerate hidden network devices or publish rogue control commands.

Publication Date June 4, 2026, 1:17 p.m.
Registration Date June 5, 2026, 4:10 a.m.
Last Update June 5, 2026, 12:10 a.m.
Related information, measures and tools
Common Vulnerabilities List