PT-2026-98925 · Vmware · Rabbitmq
CVE-2026-67420
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v4.0
2.3
Low
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
RabbitMQ versions 3.13.0 through 3.13.18
RabbitMQ versions 4.0.x through 4.0.23
RabbitMQ versions 4.1.x through 4.1.14
RabbitMQ versions 4.2.x through 4.2.9
RabbitMQ versions 4.3.x through 4.3.4
Description
An issue exists where OAuth credential refresh retains revoked runtime tags. When an existing AMQP connection refreshes from an OAuth token granting the impersonator tag to a valid token for the same username that no longer grants that tag, the system updates the OAuth backend implementation but fails to update the connection's runtime
#user.tags. Consequently, the rabbitaccesscontrol:checkuserid/2 function continues to honor the stale impersonator tag, allowing the connection and its newly opened channels to publish messages using a foreign AMQP userid after the privilege was revoked. This occurs when rabbitauthbackendoauth2 or a similar refresh-capable backend is enabled and is limited to connections that previously held the impersonator tag and refreshed to a downgraded token.Recommendations
Update RabbitMQ to version 3.13.19.
Update RabbitMQ to version 4.0.24.
Update RabbitMQ to version 4.1.15.
Update RabbitMQ to version 4.2.10.
Update RabbitMQ to version 4.3.5.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rabbitmq