PT-2026-97557 · Vmware · Rabbitmq
CVE-2026-66069
·
Published
2026-09-23
·
Updated
2026-09-23
CVSS v4.0
2.3
Low
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
RabbitMQ versions prior to 4.1.13
RabbitMQ versions prior to 4.2.7
RabbitMQ versions prior to 4.3.0
Description
An issue exists where the
is authorized/2 function uses is authorized monitor for all methods. This allows a user with the monitoring tag in the Management plugin to reset per-node authentication-attempt counters. This action is performed via the DELETE '/api/auth/attempts/:node' endpoint, which triggers the rabbit core metrics:reset auth attempt metrics() function. This can be used to erase evidence of brute-force activity, creating an inconsistency as the similar wm reset endpoint requires administrator privileges. The impact is considered cosmetic as it only affects counters and does not erase logs.Recommendations
Update to version 4.1.13.
Update to version 4.2.7.
Update to version 4.3.0.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rabbitmq