Authorization Flaw in RabbitMQ Messaging and Streaming Broker
CVE-2026-66069

2.3LOW

Key Information:

Vendor

RabbitMQ

Vendor
CVE Published:
23 September 2026

What is CVE-2026-66069?

RabbitMQ, a widely used messaging and streaming broker, contains an authorization flaw that affects versions prior to 4.1.13, 4.2.7, and 4.3.0. The vulnerability arises from the misconfiguration of authorization for the is_authorized/2 function, allowing users with monitoring permissions to reset authentication attempt counters improperly via a DELETE request to the /api/auth/attempts/:node endpoint. This operation can mask brute-force attack attempts by clearing evidence of failed login attempts, which compromises the integrity of the security monitoring process. In contrast, the related endpoint wm_reset mandates administrator-level permissions, highlighting the inconsistency in privilege requirements. To mitigate this flaw, upgrade to the patched versions 4.1.13, 4.2.7, and 4.3.0 immediately.

Affected Version(s)

rabbitmq-server >= 4.1.0, < 4.1.13 < 4.1.0, 4.1.13

rabbitmq-server >= 4.2.0, < 4.2.7 < 4.2.0, 4.2.7

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.