PT-2026-98900 · Vmware · Rabbitmq

CVE-2026-61837

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions RabbitMQ versions 4.0.0 through 4.0.22 RabbitMQ versions 4.1.0 through 4.1.13 RabbitMQ versions 4.2.0 through 4.2.8 RabbitMQ versions 4.3.0 through 4.3.2
Description An issue exists in the AMQP 1.0 HTTP-over-AMQP management endpoint GET /bindings (handled by the rabbitamqpmanagement handler) where it enumerates bindings between a source exchange and a destination queue or exchange within the caller's virtual host without performing resource-level permission checks. While other operations in the same module utilize checkresourceaccess() or bindingchecks(), this specific handler ignores the authenticated user's permissions. Consequently, any authenticated AMQP 1.0 client, including those without management, monitoring, policymaker, or administrator tags, can enumerate the complete binding topology, including source exchanges, destination queues/exchanges, routing keys, and binding arguments. This also affects the equivalent HTTP management API endpoint GET /api/bindings.
Recommendations Update to version 4.0.23 Update to version 4.1.14 Update to version 4.2.9 Update to version 4.3.3

Exploit

Fix

Missing Authorization

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61837
GHSA-W9HF-476R-443X

Affected Products

Rabbitmq