CVE-2026-25768: 84codes Lavinmq
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
LavinMQ is a high-performance message queue & streaming server. Before 2.6.6, an authenticated user could access metadata in the broker they should not have access to. This vulnerability is fixed in 2.6.6.
Affected products
- 84codes Lavinmq: before 2.6.6 (fixed in 2.6.6)
Published 2026-02-12. Last modified 2026-06-17.