Improper access control in RabbitMQ Server - #VU143932

 

Improper access control in RabbitMQ Server - #VU143932

Published: August 18, 2026


Vulnerability identifier: #VU143932
CSH Severity: Low
CVSS v4: 5.9 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper access control in the RabbitMQ management HTTP API and Erlang distribution handling when processing administrator-authenticated global-parameter and reset requests that trigger outbound distribution handshakes to attacker-controlled nodes. A remote privileged user can send specially crafted management API requests and reflect distribution authentication responses to execute arbitrary code.

Exploitation requires valid management credentials with the administrator tag, reachable management reset and global-parameter routes, broker resolution of an attacker-controlled hostname, and broker egress to attacker-controlled EPMD and distribution ports.


Affected software

RabbitMQ Server

Remediation

Install security update from vendor's website.

RabbitMQ Server - addressed in versions 3.13.19, 4.0.24, 4.1.15, 4.2.10, 4.3.5

External References

Related Security Bulletins