← Terug naar overzicht

CVE-2026-69658 describes a vulnerability where MQTT credentials and control traffic are transmitted in cleartext over the network. This exposes sensitive authentication information to any attacker with network-level access. The vulnerability could allow unauthorized actors to intercept credentials and impersonate legitimate devices. Additionally, disruption of messaging functions is a potential consequence of exploitation. The issue is classified as high severity and is relevant to OT/ICS environments. It is documented by both CISA and the NVD, with an associated ICS advisory (ICSA-26-237-06). The lack of encryption in MQTT communications represents a fundamental security design flaw. Organizations using affected MQTT implementations should apply mitigations immediately.

Affected products

  • MQTT

Related CVE's

  • CVE-2026-69658

Categories

  • Critical Infrastructure
  • Mobile & IoT
  • Network Infrastructure