Protected Tag Bypass in RabbitMQ Messaging Broker
CVE-2026-66078
2.1LOW
What is CVE-2026-66078?
A significant vulnerability in RabbitMQ allows authorized administrators to bypass the safeguarded deletion of protected-tagged users through a bulk-delete API call. The affected versions fail to enforce protected user tags when executing deletions, creating a potential security risk by allowing unintended deletions of sensitive user accounts. This issue has been addressed in the latest versions of the RabbitMQ messaging broker, ensuring that protected users remain secure.
Affected Version(s)
rabbitmq-server >= 3.13.0, < 3.13.15 < 3.13.0, 3.13.15
rabbitmq-server >= 4.0.0, < 4.0.20 < 4.0.0, 4.0.20
rabbitmq-server >= 4.1.0, < 4.1.11 < 4.1.0, 4.1.11
