CVE-2026-79391: Trueview Trueview 6.0.23.4 vulnerability
Published Sep 4, 2026
·Updated
No authentication exists in the MQTT service of Trueview 6.0.23.4. The MQTT broker accepts client connections on TCP port 1883 without requiring authentication, allowing a remote attacker with network access to establish an MQTT session and perform unauthorized publish or subscribe operations.
Affected Software
1 affected component
Trueview Trueview 6.0.23.4=6.0.23.4
Event History
Sep 4, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
Who can exploit this issue?
Any remote attacker with network access to the Trueview MQTT broker can connect to TCP port 1883. No MQTT authentication is required.
2
What unauthorized actions can an attacker perform after connecting?
An attacker can establish an MQTT session and perform publish or subscribe operations without authorization.
3
How can I determine whether an instance is exposed?
Check whether the Trueview MQTT service is reachable on TCP port 1883 from untrusted networks and accepts MQTT client connections without authentication.