Authorization Bypass in RabbitMQ Messaging Broker
CVE-2026-66075

2.3LOW

Key Information:

Vendor

RabbitMQ

Vendor
CVE Published:
23 September 2026

What is CVE-2026-66075?

A vulnerability in RabbitMQ messaging broker allows users with read-only monitoring credentials to restart federation links, disrupting message flow. This flaw arises from inadequate method-specific elevation checks in the is_authorized/2 function, enabling unauthorized operations when certain plugins are active. Fixed in recent updates, this issue underscores the importance of properly managing user permissions and monitoring access within messaging systems.

Affected Version(s)

rabbitmq-server >= 3.13.0, < 3.13.15 < 3.13.0, 3.13.15

rabbitmq-server >= 4.0.0, < 4.0.20 < 4.0.0, 4.0.20

rabbitmq-server >= 4.1.0, < 4.1.11 < 4.1.0, 4.1.11

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.