Missing Authorization in RabbitMQ Server - #VU137256
Published: July 9, 2026
Vulnerability details
The vulnerability allows a remote user to delete or restart dynamic shovels.
The vulnerability exists due to improper access control in the shovel management resource when handling DELETE requests to the shovels API endpoint. A remote user can send a crafted DELETE request to delete or restart dynamic shovels.
Only instances with the rabbitmq_shovel and rabbitmq_shovel_management plugins enabled are vulnerable.