Improper access control in RabbitMQ Server - #VU143932
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper access control in the RabbitMQ management HTTP API and Erlang distribution handling when processing administrator-authenticated global-parameter and reset requests that trigger outbound distribution handshakes to attacker-controlled nodes. A remote privileged user can send specially crafted management API requests and reflect distribution authentication responses to execute arbitrary code.
Exploitation requires valid management credentials with the administrator tag, reachable management reset and global-parameter routes, broker resolution of an attacker-controlled hostname, and broker egress to attacker-controlled EPMD and distribution ports.