Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-67412

Опубликовано: 25 сент. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 4.3.3, 4.2.9 , 4.1.14, 4.0.24, and 3.13.18, Federation upstream in RabbitMQ skips vhost authorization allowing cross-vhost message access. what the bug lets you do. A policymaker on one vhost reads and drains messages out of another vhost it has no permission on. With the default ack-mode the source messages are consumed (deleted), not copied. Why that should not 1. Federation validates the upstream URI without any vhost-access Cross-vhost message read/drain from a per-vhost policymaker, breaking vhost tenancy This issue is fixed in versions 4.3.3, 4.2.9 , 4.1.14, 4.0.24, and 3.13.18.

A flaw was found in RabbitMQ. The Federation feature fails to enforce virtual host (vhost) authorization checks when validating upstream connections. An authenticated user with policy configuration privileges in one vhost can exploit this flaw by targeting another vhost where they lack permissions. This allows the user to read and drain (delete) messages from unauthorized vhosts, compromising multi-tenant isolation and leading to unauthorized data disclosure and message loss.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Hardened Imagesrabbitmq-server4.2Will not fix
Red Hat OpenStack Platform 13 (Queens)rabbitmq-serverOut of support scope
Red Hat OpenStack Platform 16.2rabbitmq-serverOut of support scope
Red Hat OpenStack Platform 17.1rabbitmq-serverOut of support scope
Red Hat OpenStack Platform 18.0rabbitmq-serverFix deferred
Red Hat Hardened Imagesrabbitmq-server4-3-main-4.3.6-1.hum1FixedRHSA-2026:6755215.09.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-639
https://bugzilla.redhat.com/show_bug.cgi?id=2541507rabbitmq-server: RabbitMQ: Unauthorized cross-vhost message access via missing Federation upstream authorization

EPSS

Процентиль: 21%
0.00302
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

ubuntu
8 дней назад

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 4.3.3, 4.2.9 , 4.1.14, 4.0.24, and 3.13.18, Federation upstream in RabbitMQ skips vhost authorization allowing cross-vhost message access. what the bug lets you do. A policymaker on one vhost reads and drains messages out of another vhost it has no permission on. With the default ack-mode the source messages are consumed (deleted), not copied. Why that should not 1. Federation validates the upstream URI without any vhost-access Cross-vhost message read/drain from a per-vhost policymaker, breaking vhost tenancy This issue is fixed in versions 4.3.3, 4.2.9 , 4.1.14, 4.0.24, and 3.13.18.

nvd
8 дней назад

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 4.3.3, 4.2.9 , 4.1.14, 4.0.24, and 3.13.18, Federation upstream in RabbitMQ skips vhost authorization allowing cross-vhost message access. what the bug lets you do. A policymaker on one vhost reads and drains messages out of another vhost it has no permission on. With the default ack-mode the source messages are consumed (deleted), not copied. Why that should not 1. Federation validates the upstream URI without any vhost-access Cross-vhost message read/drain from a per-vhost policymaker, breaking vhost tenancy This issue is fixed in versions 4.3.3, 4.2.9 , 4.1.14, 4.0.24, and 3.13.18.

msrc
3 дня назад

RabbitMQ: Federation upstream skips vhost authorization allowing cross-vhost message access

debian
8 дней назад

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 4.3.3, ...

github
2 месяца назад

Federation upstream in RabbitMQ skips vhost authorization allowing cross-vhost message access

EPSS

Процентиль: 21%
0.00302
Низкий

6.5 Medium

CVSS3