CVE-2026-8741: EMQX QoS 2 PUBLISH Packet emqx_persistent_session_ds.erl race condition
A vulnerability has been found in EMQX up to 6.2.0. This affects an unknown function of the file apps/emqx/src/emqxpersistentsessionds.erl of the component QoS 2 PUBLISH Packet Handler. Such manipulation leads to race condition. The attack may be performed from remote. A high complexity level is associated with this attack. The exploitability is reported as difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict remote access to EMQX instances until a vendor fix is available. Implement firewall rules, VPN access, or network segmentation to allow only trusted IPs to reach EMQX services and management interfaces; block or limit Internet-exposed access.
- Operational
Monitor EMQX logs and telemetry for anomalous activity that could indicate exploitation of the disclosed QoS 2 PUBLISH race condition. If compromise is suspected, isolate affected hosts and perform incident response. Track vendor advisories and apply the vendor-provided patch or remediation as soon as it is published.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8741?
CVE-2026-8741 has a severity rating that is currently under review due to its potential impact on the QoS 2 PUBLISH Packet Handler.
How do I fix CVE-2026-8741?
To fix CVE-2026-8741, users should upgrade to EMQX version 6.2.1 or later.
What components are affected by CVE-2026-8741?
CVE-2026-8741 affects the QoS 2 PUBLISH Packet Handler in EMQX versions up to 6.2.0.
What type of vulnerability is CVE-2026-8741?
CVE-2026-8741 is classified as a race condition vulnerability.
What can attackers achieve by exploiting CVE-2026-8741?
By exploiting CVE-2026-8741, attackers can manipulate the QoS 2 PUBLISH Packet processing, leading to potential disruptions in message delivery.