Missing Authorization in RabbitMQ Server - #VU137253
Published: July 9, 2026
Vulnerability details
The vulnerability allows a remote user to delete protected-tagged service accounts.
The vulnerability exists due to missing authorization in the bulk-delete endpoint when processing bulk user deletion requests. A remote privileged user can send a specially crafted bulk-delete request to delete protected-tagged service accounts.
Exploitation requires the management plugin to be enabled and a protected-tagged user to exist.