Cross-Vhost Messaging Issue in RabbitMQ by Pivotal Software
CVE-2026-67412
6MEDIUM
What is CVE-2026-67412?
A vulnerability in RabbitMQ allows users with access to one virtual host (vhost) to read and drain messages from another vhost without permission. This occurs due to improper authorization checks when federating upstream connections, leading to violations of intended vhost isolation policies. As a result, messages can be deleted instead of copied, posing significant risks to data integrity and security. This issue has been resolved in recent updates, specifically versions 4.3.3, 4.2.9, 4.1.14, 4.0.24, and 3.13.18.
Affected Version(s)
rabbitmq-server >= 4.3.0, < 4.3.3 < 4.3.0, 4.3.3
rabbitmq-server >= 4.2.0, < 4.2.9 < 4.2.0, 4.2.9
rabbitmq-server >= 4.1.0, < 4.1.14 < 4.1.0, 4.1.14
