{"id":"CVE-2026-44725","summary":"EMQX: Stale plugins allow grants amplify a compromised admin/API key to remote code execution","details":"EMQX is a scalable and reliable MQTT broker for AI, IoT, IIoT, and connected vehicles. Prior to versions 5.8.11, 5.9.3, 5.10.4, 6.0.3, 6.1.2, and 6.2.1, the plugin-install REST API and dashboard upload accepted stale grants created with emqx ctl plugins allow because there was no five-minute grant lifetime or SHA-256 package binding. An attacker with a compromised dashboard administrator credential or API key with plugin-install permission who finds a stale allowed name and version can upload attacker-controlled bytes under the allowed .tar.gz filename through POST /api/v5/plugins/install or the dashboard plugin upload. The broker then installs and runs attacker-controlled Erlang code with the privileges of the EMQX process. This issue is fixed in versions 5.8.11, 5.9.3, 5.10.4, 6.0.3, 6.1.2, and 6.2.1.","aliases":["GHSA-cp9x-5qwc-fj6r"],"modified":"2026-08-23T03:42:43.585965619Z","published":"2026-08-20T14:35:11.726Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44725.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-345","CWE-672"]},"references":[{"type":"WEB","url":"https://github.com/emqx/emqx/releases/tag/6.0.3"},{"type":"WEB","url":"https://github.com/emqx/emqx/releases/tag/6.1.2"},{"type":"WEB","url":"https://github.com/emqx/emqx/releases/tag/6.2.1"},{"type":"WEB","url":"https://github.com/emqx/emqx/releases/tag/e5.10.4"},{"type":"WEB","url":"https://github.com/emqx/emqx/releases/tag/e5.8.11"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44725.json"},{"type":"ADVISORY","url":"https://github.com/emqx/emqx/security/advisories/GHSA-cp9x-5qwc-fj6r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44725"},{"type":"FIX","url":"https://github.com/emqx/emqx/commit/2f926359fa847dd9928a8e94d3e342f5621806f4"},{"type":"FIX","url":"https://github.com/emqx/emqx/commit/efa1ca1bef1517f1f87e1d562f8db8750b6d6ce3"},{"type":"FIX","url":"https://github.com/emqx/emqx/pull/17200"},{"type":"FIX","url":"https://github.com/emqx/emqx/pull/17201"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/emqx/emqx","events":[{"introduced":"0"},{"introduced":"b2443ba3d1782a32e018f717311c5c49de687ed3"},{"introduced":"b3cbc08540e2af324ec8ee49ee0813494365b9f3"},{"introduced":"b15e6dc7193207a0709f0caa79f9c69cbadbbe8c"},{"introduced":"7ed38516e9acc30de06fa32b8d2e659520d7d85c"},{"introduced":"5f205e1b301d7aee80e72c1c4d44e71f2a4793d6"},{"fixed":"bb073703d48fc0e5694256e13e2e2fe8535fba51"},{"fixed":"5d155d516ca7cb462d47c22feb7961135ad1eea5"},{"fixed":"416bc5cf62ff72845baec5ca095f8c472cbd712d"},{"fixed":"073b31b88e65dcf4a7f461e0374fa1689a055ca7"},{"fixed":"5b29a7101af9269d13fea6bfbf31b8b53dc1feab"},{"fixed":"65cbf01efa5224119f8bd1f801e43664481ccc97"},{"fixed":"2f926359fa847dd9928a8e94d3e342f5621806f4"},{"fixed":"efa1ca1bef1517f1f87e1d562f8db8750b6d6ce3"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"5.8.11"},{"introduced":"5.9.0"},{"fixed":"5.9.3"},{"introduced":"5.10.0"},{"fixed":"5.10.4"},{"introduced":"6.0.0"},{"fixed":"6.0.3"},{"introduced":"6.1.0"},{"fixed":"6.1.2"},{"introduced":"6.2.0"},{"fixed":"6.2.1"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["e5.8.11-rc.1","6.0.3-rc.1","6.1.2-rc.4","e5.10.4-rc.5","6.2.1-rc.1","e5.10.4-rc.4","e5.8.10","e5.10.4-rc.3","e5.10.4-rc.2","e5.10.1","6.1.2-rc.3","6.1.2-rc.2","e5.8.10-rc.2","e5.8.10-rc.1","6.2.0","6.1.2-rc.1","6.1.1","6.1.1-rc.5","6.1.1-rc.4","6.1.1-rc.2","e5.10.3","e5.10.3-rc.4","e5.10.3-rc.3","e5.10.3-rc.2","6.0.2","6.0.2-rc.1","6.1.1-rc.1","e5.10.3-rc.1","v5.8.9","e5.8.9","e5.8.9-rc.1","e5.10.3-alpha.1","6.1.0","e6.0.2-beta.2","e6.0.2-beta.1","e5.10.2","e5.9.2","e6.0.1","6.0.1","e6.0.1-rc.2","e5.10.2-rc.2","e5.10.2-rc.1","e6.0.1-rc.1","v5.8.6","e5.10.2-alpha.1","e6.0.1-alpha.2","e6.0.1-alpha.1","e6.0.0","6.0.0","e5.10.1-rc.2","e5.10.1-rc.1","e5.9.0","e5.9.2-beta.3","v5.8.8","e5.8.8","v5.8.8-rc.1","e5.8.8-rc.1","e5.9.2-beta.2","e5.10.1-beta.2","v5.8.8-beta.2","e5.10.1-beta.1","e5.9.2-beta.1","v5.8.8-beta.1","v5.8.7","e5.9.1","e5.9.1-rc.1","e5.9.1-alpha.1","e5.10.0","v5.8.5","v5.8.4","v5.8.4-beta.1","v5.8.3","v5.8.3-rc.2","v5.8.3-rc.1","v5.8.2","v5.8.2-rc.1","v5.8.2-beta.1","v5.8.1","v5.8.1-rc.2","v5.8.1-rc.1","v5.8.1-beta.2","v5.8.0","v5.8.0-rc.2","v5.8.0-alpha.1","e5.0.0-beta.6","v5.0.10","v5.0.5-beta.1","v5.0.3","v5.0.2","v5.0.1","v5.0.1-beta.1","v5.0.0","v5.0.0-rc.4","v5.0.0-rc.3","v5.0.0-rc.2","v5.0.0-rc.1","v5.0.0-beta.4","v5.0-beta.2","v5.0-beta.1","5.0-beta.1","v5.0-alpha.6","5.0-alpha.6","v5.0-alpha.5","5.0-alpha.5","v5.0-alpha.4","5.0-alpha.4","v5.0-alpha.3","5.0-alpha.3","v5.0-alpha.2","5.0-alpha.2","v5.0-alpha.1","5.0-alpha.1","v4.3.3","4.3.3","v4.3.2","4.3.2","v4.3.1","4.3.1","v4.3.0","4.3.0","v4.3-rc.5","v4.3-rc.4","4.3-rc.4","v4.3-rc.3","4.3-rc.3","v4.3-rc.2","v4.3-rc.1","4.3-rc.1","v4.3-beta.1","4.3-beta.1","v4.3-alpha.1","4.3-alpha.1","v4.2.3","4.2.3","v4.2.2","4.2.2","v4.2.1","4.2.1","v4.2.0","4.2.0","v4.2-rc.2","4.2-rc.2","v4.2-rc.1","4.2-rc.1","v4.2-beta.1","4.2-beta.1","v4.2-alpha.3","4.2-alpha.3","v4.2-alpha.2","4.2-alpha.2","v4.2-alpha.1","4.2-alpha.1","v4.1.0","v2.3.11","v2.3.10","v2.3.9","v2.3.8","v2.3.7","v2.3.6","v2.3.5","v2.3.4","v2.3.3","v2.3.2","v2.3.1","v2.3.0","v2.3-rc.2","v2.3-rc.1","v2.3-beta.4","v2.3-beta.3","v2.3-beta.2","v2.3-beta.1","v2.2.0","v2.2-rc.2","v2.2-rc.1","v2.2-beta.3","v2.2-beta.2","v2.2-beta.1","v2.1.2","v2.1.1","v2.1.0","v2.1.0-rc.2","v2.1.0-rc.1","v2.1.0-beta.2","v2.1.0-beta.1","v2.1","v2.0.7","v2.0.6","v2.0.5","v2.0.4","v2.0.3","v2.0.2","v2.0.1","v2.0","v2.0-rc.3","v2.0-rc.2","v2.0-rc.1","v2.0-beta.3","v2.0-beta.2","v2.0-beta.1","1.1.3","1.1.2","1.1.1","1.1","1.0.3","1.0.2","1.0.1","1.0","0.17.1","0.17.0","0.16.0","0.15.0","0.14.1-beta","0.14.0-beta","0.13.1-beta","0.13.0-beta","0.12.3-beta","0.12.1-beta","0.12.0-beta","0.11.0-beta","0.10.4-beta","0.10.3-beta","0.10.2-beta","0.10.1-beta","0.10.0-beta","0.9.2-alpha","0.9.1","0.9.0-alpha","0.8.0-alpha","0.7.0-alpha","0.6.1-alpha","0.6.0-alpha","0.5.2-alpha","v0.5.1-alpha","v0.4.0-alpha","v0.3.2-beta","v0.3.1-beta","v0.2.1-beta","0.2.0","0.1.6","0.1.5","0.1.4","0.1.3","0.1.2","0.1.1","0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44725.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}