Missing Authorization in RabbitMQ Server - #VU137234

 

Missing Authorization in RabbitMQ Server - #VU137234

Published: July 9, 2026


Vulnerability identifier: #VU137234
CSH Severity: Low
CVSS v4 BT: 1.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: N/A
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to modify the integrity of authentication-attempt metrics.

The vulnerability exists due to missing authorization in the auth-attempt metrics DELETE endpoint when handling DELETE requests to /api/auth/attempts/:node. A remote user can send a DELETE request to reset per-node authentication-attempt counters to modify the integrity of authentication-attempt metrics.

The issue affects counters only and does not erase logs. Exploitation requires the management plugin to be enabled.


Affected software

RabbitMQ Server

Remediation

Install security update from vendor's website.

RabbitMQ Server - addressed in versions 4.2.0 beta.1, 4.2.7

External References

Related Security Bulletins