MEDIUM
emqx
CVE published 2026-08-20
CVE-2026-44725
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-20T15:17:30.003Z and has not been modified since then. The EMQX plugin-install REST API and dashboard upload are vulnerable to code execution due to improper validation of plugin installations. An attacker with compromised dashboard administrator credentials or an API key with plugin-install permiss [truncated]