Missing Authorization in RabbitMQ Server - CVE-2026-61837

 

Missing Authorization in RabbitMQ Server - CVE-2026-61837

Published: July 24, 2026


Vulnerability identifier: #VU139299
CSH Severity: Low
CVSS v4 BT: 4.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2026-61837
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to missing authorization in the AMQP 1.0 HTTP-over-AMQP management endpoint GET /bindings when handling management requests over an AMQP 1.0 management link pair. A remote user can send a specially crafted GET /bindings request to disclose sensitive information.

The issue exposes binding topology within the virtual host, including source and destination names, routing keys, binding arguments, and binding location URIs.


Affected software

RabbitMQ Server

How to mitigate CVE-2026-61837

Install security update from vendor's website.

RabbitMQ Server - addressed in versions 4.0.23, 4.1.14, 4.2.9, 4.3.3

External References

Related Security Bulletins