CVE-2026-79391

No authentication exists in the MQTT service of Trueview 6.0.23.4. The MQTT broker accepts client connections on TCP port 1883 without requiring authentication, allowing a remote attacker with network access to establish an MQTT session and perform unauthorized publish or subscribe operations.

  • Published Sep 4, 2026
  • CVSS 9.8 critical
  • 0.7% chance of exploitation in the next 30 days (EPSS)

CVE-2026-79391 at the National Vulnerability Database