PT-2026-98913 · Vmware · Rabbitmq
CVE-2026-67241
·
Published
2026-09-25
·
Updated
2026-09-29
CVSS v4.0
4.8
Medium
| Vector | AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
RabbitMQ versions 4.2.0 through 4.2.8
RabbitMQ versions 4.3.0 through 4.3.2
Description
In the AMQP 1.0 management
exchange.declare process, the system fails to perform a permission check for the alternate-exchange argument. Specifically, the PUT /exchanges/:name endpoint only verifies the configure permission on the declared exchange and passes arguments directly to the rabbitexchange:declare/7 function, omitting the checkreadpermitted(X) and checkwritepermitted(AE) checks required for the alternate-exchange argument. This allows a user who possesses only configure permissions on an exchange to route unroutable messages into an alternate exchange for which they lack write permissions.Recommendations
Update RabbitMQ to version 4.2.9.
Update RabbitMQ to version 4.3.3.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rabbitmq