PT-2026-98905 · Vmware · Rabbitmq

CVE-2026-67223

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v4.0

6.3

Medium

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions RabbitMQ versions prior to 3.13.18 RabbitMQ versions prior to 4.0.23 RabbitMQ versions prior to 4.1.14 RabbitMQ versions prior to 4.2.9 RabbitMQ versions prior to 4.3.3
Description An issue exists where the fill/2 function substitutes the ${username} variable into the user dn pattern without proper RFC 4514 Distinguished Name (DN) escaping. This allows a crafted username to alter the LDAP bind DN, potentially enabling the selection of a different directory entry. Successful exploitation requires the use of rabbitmq auth backend ldap with a user dn pattern containing ${username}, a directory layout where the injected suffix resolves effectively, and a password valid for the resulting DN.
Recommendations Update to version 3.13.18 or later. Update to version 4.0.23 or later. Update to version 4.1.14 or later. Update to version 4.2.9 or later. Update to version 4.3.3 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67223
GHSA-9X7R-G78C-5835

Affected Products

Rabbitmq