PT-2026-97579 · Vmware+1 · Rabbitmq+1

CVE-2026-67218

·

Published

2026-09-23

·

Updated

2026-09-24

CVSS v4.0

2.1

Low

VectorAV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions RabbitMQ versions prior to 4.0.22 RabbitMQ versions prior to 4.1.11 RabbitMQ versions prior to 4.2.6 RabbitMQ versions prior to 4.3.0
Description An issue exists in the HTTP handler of the rabbitmq stream management plugin where the accept content/2 function calls rabbit stream manager:create super stream/... without properly verifying configuration permissions. While the stream-protocol path uses rabbit stream utils:check super stream management permitted/4 to enforce permissions on the exchange and partition queues, the HTTP path omits this check. Consequently, a user possessing only the management tag and vhost access, but lacking configure permissions on any resource, can create super-streams (consisting of an exchange, N partition stream queues, and bindings) via the HTTP API. This results in a privilege escalation from a view-only role to the ability to create persistent cluster-wide resources.
Recommendations Update to version 4.0.22. Update to version 4.1.11. Update to version 4.2.6. Update to version 4.3.0. As a temporary mitigation, disable the rabbitmq stream management plugin.

Exploit

Fix

LPE

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67218
GHSA-34JW-RM7G-HPH4

Affected Products

Rabbitmq
Rabbitmq Stream Management