Improper access control in RabbitMQ Server - #VU143931
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary BEAM function calls.
The vulnerability exists due to improper access control in the federation-management restart resource when handling crafted federation restart requests for nonmember Erlang nodes. A remote user can send concurrent crafted requests that trigger nonmember RPC calls and reflect distribution handshake digests to execute arbitrary BEAM function calls.
Exploitation requires valid management credentials with the policymaker tag, permission for the selected vhost, the rabbitmq_federation and rabbitmq_federation_management plugins enabled, broker reachability to attacker-controlled EPMD and distribution ports, and the tested OTP 27 handshake behavior.