PT-2026-97859 · Vmware · Rabbitmq

CVE-2026-67233

·

Published

2026-09-24

·

Updated

2026-09-24

CVSS v4.0

6.0

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions RabbitMQ versions prior to 3.13.15 RabbitMQ versions prior to 4.0.20 RabbitMQ versions prior to 4.1.11 RabbitMQ versions prior to 4.2.6 RabbitMQ versions prior to 4.3.1
Description An authorization bypass exists in the shovel management resource where the is authorized/2 function delegates to rabbit mgmt util:is authorized monitor/2. Because the allowed methods list includes DELETE and the delete resource/2 function performs deletions or restarts of shovel runtime parameters without additional role checks, a user with only the monitoring tag can perform state-changing operations. This allows a read-only monitoring user to delete or restart any dynamic shovel in any vhost they can access, an action that should be restricted to a policymaker. This issue requires the rabbitmq shovel and rabbitmq shovel management plugins to be enabled and the attacker to possess credentials with the monitoring tag.
Recommendations Update to version 3.13.15. Update to version 4.0.20. Update to version 4.1.11. Update to version 4.2.6. Update to version 4.3.1.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67233
GHSA-7JC3-73V6-RJVC

Affected Products

Rabbitmq