PT-2026-97579 · Vmware+1 · Rabbitmq+1
CVE-2026-67218
·
Published
2026-09-23
·
Updated
2026-09-24
CVSS v4.0
2.1
Low
| Vector | AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
RabbitMQ versions prior to 4.0.22
RabbitMQ versions prior to 4.1.11
RabbitMQ versions prior to 4.2.6
RabbitMQ versions prior to 4.3.0
Description
An issue exists in the HTTP handler of the
rabbitmq stream management plugin where the accept content/2 function calls rabbit stream manager:create super stream/... without properly verifying configuration permissions. While the stream-protocol path uses rabbit stream utils:check super stream management permitted/4 to enforce permissions on the exchange and partition queues, the HTTP path omits this check. Consequently, a user possessing only the management tag and vhost access, but lacking configure permissions on any resource, can create super-streams (consisting of an exchange, N partition stream queues, and bindings) via the HTTP API. This results in a privilege escalation from a view-only role to the ability to create persistent cluster-wide resources.Recommendations
Update to version 4.0.22.
Update to version 4.1.11.
Update to version 4.2.6.
Update to version 4.3.0.
As a temporary mitigation, disable the
rabbitmq stream management plugin.Exploit
Fix
LPE
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rabbitmq
Rabbitmq Stream Management