PT-2026-98900 · Vmware · Rabbitmq
CVE-2026-61837
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
RabbitMQ versions 4.0.0 through 4.0.22
RabbitMQ versions 4.1.0 through 4.1.13
RabbitMQ versions 4.2.0 through 4.2.8
RabbitMQ versions 4.3.0 through 4.3.2
Description
An issue exists in the AMQP 1.0 HTTP-over-AMQP management endpoint
GET /bindings (handled by the rabbitamqpmanagement handler) where it enumerates bindings between a source exchange and a destination queue or exchange within the caller's virtual host without performing resource-level permission checks. While other operations in the same module utilize checkresourceaccess() or bindingchecks(), this specific handler ignores the authenticated user's permissions. Consequently, any authenticated AMQP 1.0 client, including those without management, monitoring, policymaker, or administrator tags, can enumerate the complete binding topology, including source exchanges, destination queues/exchanges, routing keys, and binding arguments. This also affects the equivalent HTTP management API endpoint GET /api/bindings.Recommendations
Update to version 4.0.23
Update to version 4.1.14
Update to version 4.2.9
Update to version 4.3.3
Exploit
Fix
Missing Authorization
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rabbitmq