PT-2026-98925 · Vmware · Rabbitmq

CVE-2026-67420

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v4.0

2.3

Low

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions RabbitMQ versions 3.13.0 through 3.13.18 RabbitMQ versions 4.0.x through 4.0.23 RabbitMQ versions 4.1.x through 4.1.14 RabbitMQ versions 4.2.x through 4.2.9 RabbitMQ versions 4.3.x through 4.3.4
Description An issue exists where OAuth credential refresh retains revoked runtime tags. When an existing AMQP connection refreshes from an OAuth token granting the impersonator tag to a valid token for the same username that no longer grants that tag, the system updates the OAuth backend implementation but fails to update the connection's runtime #user.tags. Consequently, the rabbitaccesscontrol:checkuserid/2 function continues to honor the stale impersonator tag, allowing the connection and its newly opened channels to publish messages using a foreign AMQP userid after the privilege was revoked. This occurs when rabbitauthbackendoauth2 or a similar refresh-capable backend is enabled and is limited to connections that previously held the impersonator tag and refreshed to a downgraded token.
Recommendations Update RabbitMQ to version 3.13.19. Update RabbitMQ to version 4.0.24. Update RabbitMQ to version 4.1.15. Update RabbitMQ to version 4.2.10. Update RabbitMQ to version 4.3.5.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67420
GHSA-86FM-44M9-RQJX

Affected Products

Rabbitmq