PT-2026-57306 · Vmware+1 · Rabbitmq

CVE-2026-57221

·

Published

2026-07-10

·

Updated

2026-07-24

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions RabbitMQ versions prior to 3.13.15 RabbitMQ versions prior to 4.0.20 RabbitMQ versions prior to 4.1.11 RabbitMQ versions prior to 4.2.6
Description RabbitMQ fails to perform authorization checks on passive queue.declare and exchange.declare AMQP 0-9-1 operations. This allows any authenticated user with access to a virtual host to enumerate queue and exchange names, as well as read consumer counts and the number of messages in a queue.
Recommendations Update to version 3.13.15 Update to version 4.0.20 Update to version 4.1.11 Update to version 4.2.6

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92355
CVE-2026-57221
GHSA-9Q2J-2HQ8-22R2
RHSA-2026:35939
RHSA-2026:35940

Affected Products

Rabbitmq