Improper access control in RabbitMQ Server - #VU143931

 

Improper access control in RabbitMQ Server - #VU143931

Published: August 18, 2026


Vulnerability identifier: #VU143931
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary BEAM function calls.

The vulnerability exists due to improper access control in the federation-management restart resource when handling crafted federation restart requests for nonmember Erlang nodes. A remote user can send concurrent crafted requests that trigger nonmember RPC calls and reflect distribution handshake digests to execute arbitrary BEAM function calls.

Exploitation requires valid management credentials with the policymaker tag, permission for the selected vhost, the rabbitmq_federation and rabbitmq_federation_management plugins enabled, broker reachability to attacker-controlled EPMD and distribution ports, and the tested OTP 27 handshake behavior.


Affected software

RabbitMQ Server

Remediation

Install security update from vendor's website.

RabbitMQ Server - addressed in versions 3.13.19, 4.0.24, 4.1.15, 4.2.10, 4.3.5

External References

Related Security Bulletins