Vulnerability in RabbitMQ Messaging Broker Affects Multiple Versions
CVE-2026-67411

6MEDIUM

Key Information:

Vendor

RabbitMQ

Vendor
CVE Published:
25 September 2026

What is CVE-2026-67411?

A vulnerability in RabbitMQ allows an attacker to bypass the source-address restrictions on MQTT authentication when using a trusted PROXY Protocol frontend. This issue arises in versions from 3.13.0 to 3.13.18, and several other specific releases. If an attacker is able to reach the trusted frontend and possesses valid credentials for an account restricted through loopback, they may exploit this vulnerability. Importantly, this flaw does not compromise password authentication. Fixed versions have been released to address the issue.

Affected Version(s)

rabbitmq-server >= 4.3.0, < 4.3.3 < 4.3.0, 4.3.3

rabbitmq-server >= 4.2.0, < 4.2.9 < 4.2.0, 4.2.9

rabbitmq-server >= 4.1.0, < 4.1.14 < 4.1.0, 4.1.14

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.