CVE-2026-33356 Details
Description
In Meari IoT Cloud MQTT Broker deployments running EMQX 4.x, any authenticated low-privilege account can subscribe to global wildcard topics and receive telemetry from devices the user does not own. The broker enforces publish restrictions but does not enforce equivalent subscribe authorization at per-device scope.
A vulnerability exists in Meari IoT Cloud MQTT Broker deployments using EMQX 4.x. It allows any authenticated low-privilege account to subscribe to global wildcard topics and access telemetry from devices not owned by the user. While the broker enforces publish restrictions, it fails to apply equivalent subscribe authorization on a per-device basis, breaking tenant isolation and exposing platform-wide device events across unrelated customer accounts.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 11, 2026CISA-ADP
Assessed May 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/xn0tsa/nobody-puts-baby-in-a-corner | runZero | BundleExploitTechnical Analysis |
| https://www.runzero.com/advisories/meari-mqtt-broker-missing-per-device-subscribe-acl-cve-2026-33356/ | runZero | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | runZero |
Affected Products
| Product | Versions |
|---|---|
| Meari IoT Cloud MQTT Broker | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | runZero |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 11, 2026 | New CVE Received | runZero |
Volerion