Incorrect authorization in nats-server - CVE-2026-58254

 

Incorrect authorization in nats-server - CVE-2026-58254

Published: June 30, 2026


Vulnerability identifier: #VU135935
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-58254
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass authorization checks and disclose sensitive metadata.

The vulnerability exists due to improper access control in leaf node message trace destination checks when processing messages arriving through leafnode connections. A remote user can send messages through a leafnode connection to cause trace events to be sent to subjects that would not otherwise be permitted to bypass authorization checks and disclose sensitive metadata.

Trace-only behavior can also prevent normal delivery or storage of affected messages. Trace events can include routing, subscription, account, service import, and JetStream metadata.


Affected software

nats-server

How to mitigate CVE-2026-58254

Install security update from vendor's website.

nats-server - addressed in versions 2.12.8, 2.14.3

External References

Related Security Bulletins