PT-2026-97556 · Vmware · Rabbitmq
CVE-2026-66067
·
Published
2026-09-23
·
Updated
2026-09-24
CVSS v4.0
6.0
Medium
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
RabbitMQ versions prior to 4.2.7
RabbitMQ versions prior to 4.3.1
Description
The stream open handler only executes
check vhost access and fails to perform the node, vhost, and user connection-limit checks typically handled by rabbit reader for AMQP. This omission allows an authenticated tenant to bypass operator-configured per-user and per-vhost connection caps by connecting via port 5552 instead of port 5672. This occurs when the rabbitmq stream plugin is enabled and the operator relies on these connection limits for tenant isolation.Recommendations
Update to version 4.2.7.
Update to version 4.3.1.
Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rabbitmq