PT-2026-98921 · Vmware · Rabbitmq

CVE-2026-67412

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v4.0

6.0

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions RabbitMQ versions 3.13.0 through 3.13.17 RabbitMQ versions 4.0.0 through 4.0.23 RabbitMQ versions 4.1.0 through 4.1.13 RabbitMQ versions 4.2.0 through 4.2.8 RabbitMQ versions 4.3.0 through 4.3.2
Description Federation upstream skips vhost authorization, which allows cross-vhost message access and breaks vhost tenancy. A policymaker on one vhost can read and drain messages from another vhost for which they have no permission. Using the default ack-mode results in the source messages being consumed and deleted rather than copied.
Recommendations Update to version 3.13.18 Update to version 4.0.24 Update to version 4.1.14 Update to version 4.2.9 Update to version 4.3.3

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67412
GHSA-42PC-678Q-V8QJ

Affected Products

Rabbitmq