In Meari IoT Cloud MQTT Broker deployments running EMQX 4.x, any authenticated low-privilege account can subscribe to global wildcard topics and receive telemetry from devices the user does not own. The broker enforces publish restrictions but does not enforce equivalent subscribe authorization at per-device scope.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 11 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Meari IoT Cloud MQTT Broker deployments running EMQX 4.x, any authenticated low-privilege account can subscribe to global wildcard topics and receive telemetry from devices the user does not own. The broker enforces publish restrictions but does not enforce equivalent subscribe authorization at per-device scope. | |
| Title | Meari MQTT broker missing per-device subscribe ACL | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: runZero
Published:
Updated: 2026-05-11T18:18:45.410Z
Reserved: 2026-03-19T00:27:05.986Z
Link: CVE-2026-33356
No data.
Status : Received
Published: 2026-05-11T17:16:30.590
Modified: 2026-05-11T17:16:30.590
Link: CVE-2026-33356
No data.
OpenCVE Enrichment
Updated: 2026-05-11T17:45:26Z
Weaknesses