A vulnerability was found in EMQX up to 6.2.0. It has been declared as problematic. This affects an unknown function of the file apps/emqx/src/emqx_persistent_session_ds.erl of the component QoS 2 PUBLISH Packet Handler. Such manipulation leads to race condition.
This vulnerability is listed as CVE-2026-8741. The attack may be performed from remote. In addition, an exploit is available.
The vendor was contacted early about this disclosure.