← Vulnerability feed

Vulnerability record · CVE-2024-42655 · published 29 July 2025

CVE-2024-42655: Emqx nanomq improper access control vulnerability

Emqx · Nanomq

An access control issue in NanoMQ v0.21.10 allows attackers to bypass security restrictions and access sensitive system topic messages using MQTT wildcard characters.

8.8 CVSS 3.1 High EPSS 0.36% · top 72.8% CWE-284 · Improper access control
8.8CVSS 3.1 base score
0.36%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An access control issue in NanoMQ v0.21.10 allows attackers to bypass security restrictions and access sensitive system topic messages using MQTT wildcard characters.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-42655 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.5CVE-2025-59947Emqx nanomq classic buffer overflow vulnerabilityNanoMQ is a messaging broker/bus for IoT Edge & SDV. Versions prior to 0.24.4 have a buffer overflow case while the PUBLISH packets trigger both shar…EPSS 0.33%8.2CVE-2026-34608Emqx nanomq out-of-bounds read vulnerabilityNanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.24.10, in NanoMQ's webhook_inproc.c, the hook_work_cb() func…EPSS 0.56%7.8CVE-2023-34488Emqx nanomq out-of-bounds write vulnerabilityNanoMQ 0.17.5 has a one-byte heap-based buffer over-read in the conn_handler function of mqtt_parser.c when it processes malformed messages.EPSS 0.51%7.7CVE-2026-32135Emqx nanomq heap-based buffer overflow vulnerabilityNanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.11 have a remotely triggerable heap buffer overflow in t…EPSS 0.94%7.5CVE-2026-36590Emqx nanomq uncontrolled resource consumption vulnerabilityAn issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of service via the nni_qos_db_set function in broker_tcp.c componentEPSS 0.59%7.5CVE-2026-32696Emqx nanomq null pointer dereference vulnerabilityNanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In NanoMQ version 0.24.6, after enabling auth.http_auth (HTTP authentication), …EPSS 0.56%7.5CVE-2026-25627Emqx nanomq out-of-bounds read vulnerabilityNanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.24.8, NanoMQ’s MQTT-over-WebSocket transport can be crashed …EPSS 0.60%7.5CVE-2026-21888Emqx nanomq out-of-bounds read vulnerabilityNanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. MQTT v5 Variable Byte Integer parsing out-of-bounds: get_var_integer() accepts …EPSS 0.30%

Source: NIST National Vulnerability Database (record CVE-2024-42655), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.