Cross-Vhost Messaging Issue in RabbitMQ by Pivotal Software
CVE-2026-67412

6MEDIUM

Key Information:

Vendor

RabbitMQ

Vendor
CVE Published:
25 September 2026

What is CVE-2026-67412?

A vulnerability in RabbitMQ allows users with access to one virtual host (vhost) to read and drain messages from another vhost without permission. This occurs due to improper authorization checks when federating upstream connections, leading to violations of intended vhost isolation policies. As a result, messages can be deleted instead of copied, posing significant risks to data integrity and security. This issue has been resolved in recent updates, specifically versions 4.3.3, 4.2.9, 4.1.14, 4.0.24, and 3.13.18.

Affected Version(s)

rabbitmq-server >= 4.3.0, < 4.3.3 < 4.3.0, 4.3.3

rabbitmq-server >= 4.2.0, < 4.2.9 < 4.2.0, 4.2.9

rabbitmq-server >= 4.1.0, < 4.1.14 < 4.1.0, 4.1.14

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.