PT-2026-57303 · Vmware+1 · Rabbitmq

CVE-2026-57218

·

Published

2026-07-10

·

Updated

2026-07-10

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions RabbitMQ versions prior to 4.2.6
Description RabbitMQ AMQP 0-9-1 allows an existing consumer to continue receiving messages even after an OAuth token expires or a connection.update secret refresh reduces the available scopes. This occurs because existing consumers are not canceled or reauthorized at the time of delivery following changes to the channel user state.
Recommendations Update to version 4.2.6.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92346
CVE-2026-57218
GHSA-WMRR-4H5V-5CH7
RHSA-2026:35939
RHSA-2026:35940

Affected Products

Rabbitmq