PT-2026-97565 · Vmware+1 · Rabbitmq+1
CVE-2026-67224
·
Published
2026-09-23
·
Updated
2026-09-24
CVSS v4.0
2.1
Low
| Vector | AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
RabbitMQ versions prior to 3.13.15
RabbitMQ versions prior to 4.0.20
RabbitMQ versions prior to 4.1.11
RabbitMQ versions prior to 4.2.6
RabbitMQ versions prior to 4.3.1
Description
An issue exists in the trace consumer where the output path is constructed without a safe relative path or traversal check on the write side. A user with the administrator tag can exploit this by using the
name parameter in the 'PUT /api/traces/:vhost/:name' endpoint to write a file with a .log suffix to an arbitrary filesystem path writable by the rabbitmq OS user, or overwrite existing .log files outside the trace directory. This requires the rabbitmq tracing plugin to be enabled.Recommendations
Update RabbitMQ to version 3.13.15 or later.
Update RabbitMQ to version 4.0.20 or later.
Update RabbitMQ to version 4.1.11 or later.
Update RabbitMQ to version 4.2.6 or later.
Update RabbitMQ to version 4.3.1 or later.
As a temporary mitigation, disable the
rabbitmq tracing plugin.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rabbitmq
Rabbitmq Tracing