PT-2026-57302 · Vmware+1 · Rabbitmq
CVE-2026-57217
·
Published
2026-07-10
·
Updated
2026-07-10
CVSS v4.0
7.0
High
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
RabbitMQ versions prior to 3.13.15
RabbitMQ versions prior to 4.0.21
RabbitMQ versions prior to 4.1.11
RabbitMQ versions prior to 4.2.6
Description
Topic authorization in this messaging and streaming broker may allow restricted topic writes and binds during metadata-store failures. This occurs because topic-permission lookup errors from Khepri can collapse to undefined, which the internal backend interprets as an allow permission.
Recommendations
Update to version 3.13.15
Update to version 4.0.21
Update to version 4.1.11
Update to version 4.2.6
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rabbitmq