PT-2026-57301 · Vmware+1 · Rabbitmq

CVE-2026-57216

·

Published

2026-07-10

·

Updated

2026-07-14

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RabbitMQ versions prior to 3.13.15 RabbitMQ versions prior to 4.0.20 RabbitMQ versions prior to 4.1.11 RabbitMQ versions prior to 4.2.6
Description Authentication for AMQP 0-9-1, AMQP 1.0, and Stream Protocol allows a loopback-restricted user, such as guest, to connect remotely. This occurs when traffic is accepted through a trusted PROXY-protocol path and the backend listener is loopback-bound, as the loopback check incorrectly utilizes the listener-side socket address instead of the actual client source.
Recommendations Update to version 3.13.15. Update to version 4.0.20. Update to version 4.1.11. Update to version 4.2.6.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92349
CVE-2026-57216
GHSA-36M6-588R-VQCW
RHSA-2026:35939
RHSA-2026:35940

Affected Products

Rabbitmq