Missing Authorization in RabbitMQ Server - #VU137234
Published: July 9, 2026
Vulnerability details
The vulnerability allows a remote user to modify the integrity of authentication-attempt metrics.
The vulnerability exists due to missing authorization in the auth-attempt metrics DELETE endpoint when handling DELETE requests to /api/auth/attempts/:node. A remote user can send a DELETE request to reset per-node authentication-attempt counters to modify the integrity of authentication-attempt metrics.
The issue affects counters only and does not erase logs. Exploitation requires the management plugin to be enabled.