EMQX is a scalable and reliable MQTT broker for AI, IoT, IIoT, and connected vehicles. Prior to versions 5.8.11, 5.9.3, 5.10.4, 6.0.3, 6.1.2, and 6.2.1, the plugin-install REST API and dashboard upload accepted stale grants created with emqx ctl plugins allow because there was no five-minute grant lifetime or SHA-256 package binding. An attacker with a compromised dashboard administrator credential or API key with plugin-install permission who finds a stale allowed name and version can upload attacker-controlled bytes under the allowed .tar.gz filename through POST /api/v5/plugins/install or the dashboard plugin upload. The broker then installs and runs attacker-controlled Erlang code with the privileges of the EMQX process. This issue is fixed in versions 5.8.11, 5.9.3, 5.10.4, 6.0.3, 6.1.2, and 6.2.1.
CVE-2026-44725
This medium-severity CVE scores 6.6 under a secondary CVSS source (NVD's own analysis pending). EPSS exploit probability: 0.4% (29th percentile of EPSS-scored CVEs). GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).
- Lower severity and no public exploit yet
A fix is available — apply it.
- CVSS v3
- 6.6
- EG Score
- 6.6MEDIUMmedium confidence
- EG Risk
- 30EG Risk 30/100CISA SSVC
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity66% × 45%Exploitation0% × 40%Automatability0% × 15%CISA SSVC: Track at low or medium mission impact; Track* at high (mission-essential systems).Action: A fix is available. Apply it within your standard update timelines. - EPSS PROB
- 0.4%
- EPSS %ILE
- 29th
- KEV
- Not listed
CISA SSVCTrack at low or medium mission impact; Track* at high (mission-essential systems).
A fix is available. Apply it within your standard update timelines.
Exploitation none (CISA Vulnrichment) · Automatable no (CISA Vulnrichment) · Technical impact total (CISA Vulnrichment). Mission impact is CISA's Mission & Well-being decision point, and only you can judge it: high means the affected system is essential to your organisation's mission, or its compromise could cause irreversible harm to people. CISA's decision table
Published
August 20, 2026
Last Modified
September 18, 2026
Advisory Details (10)
Auto-updated Aug 20, 2026EMQX Enterprise 5.8.11
Patch available: emqx/emqx e5.8.11
https://github.com/emqx/emqx/releases/tag/e5.8.11EMQX Enterprise 5.10.4
Patch available: emqx/emqx e5.10.4
https://github.com/emqx/emqx/releases/tag/e5.10.4EMQX Enterprise 6.2.1
Patch available: emqx/emqx 6.2.1
https://github.com/emqx/emqx/releases/tag/6.2.1EMQX Enterprise 6.1.2
Patch available: emqx/emqx 6.1.2
https://github.com/emqx/emqx/releases/tag/6.1.2EMQX Enterprise 6.0.3
Patch available: emqx/emqx 6.0.3
https://github.com/emqx/emqx/releases/tag/6.0.3commit efa1ca1bef15 (emqx/emqx)
Fix landed in emqx/emqx commit efa1ca1bef15 — awaiting tagged release
https://github.com/emqx/emqx/commit/efa1ca1bef1517f1f87e1d562f8db8750b6d6ce3commit 2f926359fa84 (emqx/emqx)
Fix landed in emqx/emqx commit 2f926359fa84 — awaiting tagged release
https://github.com/emqx/emqx/commit/2f926359fa847dd9928a8e94d3e342f5621806f4feat(plugins): TTL and sha256-pinning for install allowlist + zip-slip fix
Fix merged in emqx/emqx PR #17201 on 2026-05-05 — awaiting tagged release
https://github.com/emqx/emqx/pull/17201feat(plugins): TTL and sha256-pinning for install allowlist + zip-slip fix
Fix merged in emqx/emqx PR #17200 on 2026-05-04 — awaiting tagged release
https://github.com/emqx/emqx/pull/17200Stale plugins allow grants amplify a compromised admin/API key to remote code execution · Advisory · emqx/emqx · GitHub
https://github.com/emqx/emqx/security/advisories/GHSA-cp9x-5qwc-fj6rWeakness Classification(2)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 12× in last 7d / 48× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-10-09 20:07 UTCEPSS rescore
- 2026-10-08 17:12 UTCEPSS rescore
- 2026-10-08 05:30 UTCEG score recompute
- 2026-10-07 23:48 UTCEPSS rescore
- 2026-10-07 01:37 UTCEG score recompute
- 2026-10-06 15:18 UTCEPSS rescore
- 2026-10-06 03:28 UTCEG score recompute
- 2026-10-05 17:43 UTCEPSS rescore
- 2026-10-05 01:36 UTCEG score recompute
- 2026-10-04 23:22 UTCEPSS rescore
- 2026-10-04 03:19 UTCEG score recompute
- 2026-10-03 14:25 UTCEPSS rescore
- 2026-10-03 05:10 UTCEG score recompute
- 2026-10-02 06:49 UTCEG score recompute
- 2026-10-01 19:50 UTCEPSS rescore
- 2026-10-01 06:29 UTCEG score recompute
- 2026-09-30 15:03 UTCEPSS rescore
- 2026-09-30 08:21 UTCEG score recompute
- 2026-09-28 23:35 UTCEG score recompute
- 2026-09-28 01:27 UTCEG score recompute
- 2026-09-27 13:48 UTCEPSS rescore
- 2026-09-27 03:19 UTCEG score recompute
- 2026-09-26 15:58 UTCEPSS rescore
- 2026-09-25 07:54 UTCEG score recompute
- 2026-09-24 09:46 UTCEG score recompute
Show 58 moreShow fewer
- 2026-09-23 17:53 UTCEPSS rescore
- 2026-09-23 11:38 UTCEG score recompute
- 2026-09-22 13:29 UTCEG score recompute
- 2026-09-21 15:21 UTCEG score recompute
- 2026-09-20 20:15 UTCEPSS rescore
- 2026-09-19 18:30 UTCEG score recompute
- 2026-09-18 20:20 UTCEG score recompute
- 2026-09-18 19:28 UTCEPSS rescore
- 2026-09-18 08:04 UTCEG score recompute
- 2026-09-17 19:31 UTCEPSS rescore
- 2026-09-17 09:56 UTCEG score recompute
- 2026-09-16 14:08 UTCEPSS rescore
- 2026-09-16 11:47 UTCEG score recompute
- 2026-09-16 05:15 UTCEPSS rescore
- 2026-09-15 13:39 UTCEG score recompute
- 2026-09-13 17:23 UTCEG score recompute
- 2026-09-13 16:47 UTCEPSS rescore
- 2026-09-12 19:15 UTCEG score recompute
- 2026-09-12 15:01 UTCEPSS rescore
- 2026-09-11 21:07 UTCEG score recompute
- 2026-09-11 14:53 UTCEPSS rescore
- 2026-09-11 09:37 UTCEPSS rescore
- 2026-09-10 22:59 UTCEG score recompute
- 2026-09-10 09:34 UTCEPSS rescore
- 2026-09-09 02:00 UTCEG score recompute
- 2026-09-08 22:00 UTCEPSS rescore
- 2026-09-07 16:01 UTCEPSS rescore
- 2026-09-06 15:20 UTCEG score recompute
- 2026-09-06 13:47 UTCEPSS rescore
- 2026-09-05 17:10 UTCEG score recompute
- 2026-09-04 18:59 UTCEG score recompute
- 2026-09-04 05:06 UTCEPSS rescore
- 2026-09-02 22:40 UTCEG score recompute
- 2026-09-02 14:12 UTCEPSS rescore
- 2026-09-02 00:31 UTCEG score recompute
- 2026-09-01 13:54 UTCEPSS rescore
- 2026-08-31 04:13 UTCEG score recompute
- 2026-08-30 19:17 UTCEPSS rescore
- 2026-08-30 06:06 UTCEG score recompute
- 2026-08-30 01:22 UTCEPSS rescore
- 2026-08-29 07:56 UTCEG score recompute
- 2026-08-28 21:41 UTCEPSS rescore
- 2026-08-28 09:44 UTCEG score recompute
- 2026-08-27 14:25 UTCEPSS rescore
- 2026-08-27 11:25 UTCEG score recompute
- 2026-08-26 14:46 UTCEPSS rescore
- 2026-08-25 15:07 UTCEG score recompute
- 2026-08-25 13:49 UTCEPSS rescore
- 2026-08-24 16:57 UTCEG score recompute
- 2026-08-23 18:42 UTCEG score recompute
- 2026-08-23 00:19 UTCEPSS rescore
- 2026-08-22 20:34 UTCEG score recompute
- 2026-08-21 23:49 UTCEPSS rescore
- 2026-08-21 22:26 UTCEG score recompute
- 2026-08-21 22:00 UTCEG score recompute
- 2026-08-20 15:27 UTCEG score recompute
- 2026-08-20 14:42 UTCEG score recompute
- 2026-08-20 14:41 UTCMITRE cvelistV5first tracked
Related CVEs(same CWE)
Frequently asked(5)
What is CVE-2026-44725?
When was CVE-2026-44725 disclosed?
Is CVE-2026-44725 actively exploited?
What is the CVSS score of CVE-2026-44725?
How do I remediate CVE-2026-44725?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2026-44725
Is Your Infrastructure Affected by CVE-2026-44725?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.