Protected Tag Bypass in RabbitMQ Messaging Broker
CVE-2026-66078

2.1LOW

Key Information:

Vendor

RabbitMQ

Vendor
CVE Published:
25 September 2026

What is CVE-2026-66078?

A significant vulnerability in RabbitMQ allows authorized administrators to bypass the safeguarded deletion of protected-tagged users through a bulk-delete API call. The affected versions fail to enforce protected user tags when executing deletions, creating a potential security risk by allowing unintended deletions of sensitive user accounts. This issue has been addressed in the latest versions of the RabbitMQ messaging broker, ensuring that protected users remain secure.

Affected Version(s)

rabbitmq-server >= 3.13.0, < 3.13.15 < 3.13.0, 3.13.15

rabbitmq-server >= 4.0.0, < 4.0.20 < 4.0.0, 4.0.20

rabbitmq-server >= 4.1.0, < 4.1.11 < 4.1.0, 4.1.11

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.