PT-2026-98916 · Vmware · Rabbitmq

CVE-2026-67407

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions RabbitMQ versions 4.0.0 through 4.0.22 RabbitMQ versions 4.1.0 through 4.1.13 RabbitMQ versions 4.2.0 through 4.2.8 RabbitMQ versions 4.3.0 through 4.3.2
Description An incomplete fix in the MQTT topic permission handling allows a low-privileged authenticated user to bypass authorization. The expandtopicpermission/2 function uses escaperegexchar/1 to escape regex metacharacters in topic-permission variables, but the escaperegexchar/1 function fails to escape the hyphen (-) character. If a topic permission template places the {clientid} variable inside a [...] character class, a user controlling their clientid can broaden their read and write authorization permissions.
Recommendations Update to version 4.0.23 Update to version 4.1.14 Update to version 4.2.9 Update to version 4.3.3

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67407
GHSA-Q46V-HRVQ-HP24

Affected Products

Rabbitmq