PT-2026-97565 · Vmware+1 · Rabbitmq+1

CVE-2026-67224

·

Published

2026-09-23

·

Updated

2026-09-24

CVSS v4.0

2.1

Low

VectorAV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions RabbitMQ versions prior to 3.13.15 RabbitMQ versions prior to 4.0.20 RabbitMQ versions prior to 4.1.11 RabbitMQ versions prior to 4.2.6 RabbitMQ versions prior to 4.3.1
Description An issue exists in the trace consumer where the output path is constructed without a safe relative path or traversal check on the write side. A user with the administrator tag can exploit this by using the name parameter in the 'PUT /api/traces/:vhost/:name' endpoint to write a file with a .log suffix to an arbitrary filesystem path writable by the rabbitmq OS user, or overwrite existing .log files outside the trace directory. This requires the rabbitmq tracing plugin to be enabled.
Recommendations Update RabbitMQ to version 3.13.15 or later. Update RabbitMQ to version 4.0.20 or later. Update RabbitMQ to version 4.1.11 or later. Update RabbitMQ to version 4.2.6 or later. Update RabbitMQ to version 4.3.1 or later. As a temporary mitigation, disable the rabbitmq tracing plugin.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67224
GHSA-H7CQ-QRR8-7VGC

Affected Products

Rabbitmq
Rabbitmq Tracing