CVE-2025-52136: Emqx

Low severity, CVSS 3.0. EPSS: 0.3% chance of exploitation in the next 30 days.

In EMQX before 5.8.6, administrators can install arbitrary novel plugins via the Dashboard web interface. NOTE: the Supplier's position is that this is the intended behavior; however, 5.8.6 adds a defense-in-depth feature in which a plugin's acceptability (for later Dashboard installation) is set by the "emqx ctl plugins allow" CLI command.

Affected products

  • Emqx Emqx: before 5.8.6 (fixed in 5.8.6)

Published 2025-08-10. Last modified 2026-06-17.