PT-2026-105166 · Bitnami · Rabbitmq

Published

2026-10-01

·

Updated

2026-10-01

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
RabbitMQ is a messaging and streaming broker. Prior to versions 4.0.22, 4.1.11, 4.2.6, and 4.3.0, accept content/2 at line 56 calls rabbit stream manager:create super stream/... directly after is authorized (which only checks the management tag + vhost access via is authorized vhost). The stream-protocol equivalent (rabbit stream reader.erl create super stream handler) calls rabbit stream utils:check super stream management permitted/4 which enforces configure on the exchange and each partition queue. The HTTP handler omits this call entirely. A user with management tag and vhost access , but no configure permission on any resource , can create super-streams (an exchange + N partition stream queues + bindings) via the HTTP API. The native stream-protocol path enforces configure on each resource; the HTTP path does not, creating a privilege escalation from 'can view' to 'can create persistent cluster-wide resources.' Preconditions include rabbitmq stream management plugin enabled management tag + vhost access (no resource permissions needed). This issue is fixed in versions 4.0.22, 4.1.11, 4.2.6, and 4.3.0.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BIT-RABBITMQ-2026-67218

Affected Products

Rabbitmq