Impact
The vulnerability allows authenticated users with subscription deny permissions to subvert plain subject deny rules by using queue subscriptions with a queue that is not denied. The queue subscription can access messages on a subject that should be blocked. This creates an authorization bypass that lets an attacker read or otherwise consume data they should not be able to reach. The weakness is an access control flaw (CWE-285).
Affected Systems
Affected versions are NATS Server releases prior to 2.14.0, 2.12.7, and 2.11.16. These releases support queue subscriptions and ACLs that can be exploited. Upgrading to any of the fixed releases removes the bypass.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity impact. The EPSS score is <1%, indicating a very low but nonzero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers must be authenticated to the server and possess the appropriate ACL permissions to trigger the bypass, so exploitation is limited to environments where such permissions are granted. Nonetheless, this flaw compromises authorization controls and can expose confidential data.
OpenCVE Enrichment