Missing Authorization in RabbitMQ Server - #VU137229
Published: July 9, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in the quorum queue status management endpoint when handling GET requests to /api/queues/quorum/:vhost/:queue/status. A remote user can send a crafted request for a vhost they cannot access to disclose sensitive information.
Only instances with the management plugin enabled are vulnerable.