PT-2026-57302 · Vmware+1 · Rabbitmq

CVE-2026-57217

·

Published

2026-07-10

·

Updated

2026-07-10

CVSS v4.0

7.0

High

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions RabbitMQ versions prior to 3.13.15 RabbitMQ versions prior to 4.0.21 RabbitMQ versions prior to 4.1.11 RabbitMQ versions prior to 4.2.6
Description Topic authorization in this messaging and streaming broker may allow restricted topic writes and binds during metadata-store failures. This occurs because topic-permission lookup errors from Khepri can collapse to undefined, which the internal backend interprets as an allow permission.
Recommendations Update to version 3.13.15 Update to version 4.0.21 Update to version 4.1.11 Update to version 4.2.6

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92340
CVE-2026-57217
GHSA-GPVW-75H5-3WVX
RHSA-2026:35939
RHSA-2026:35940

Affected Products

Rabbitmq