CVE-2026-67411 — RabbitMQ is a messaging and streaming broker.
Description
RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.18, 4.0.23, 4.1.14, 4.2.9, and 4.3.3, native MQTT and MQTT over WebSocket behind a trusted PROXY Protocol frontend could lose the proxy-derived client address before the MQTT authentication path checked loopback_users, causing the frontend-to-broker address to be treated as loopback. An attacker who can reach the trusted frontend and has valid credentials for a loopback-restricted account can therefore bypass the source-address restriction; the issue does not bypass password authentication. This issue is fixed in versions 3.13.18, 4.0.23, 4.1.14, 4.2.9, and 4.3.3.
CVSS v4.0 base metrics
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
High
Attack Complexity
AT
Present
Attack Requirements
PR
Low
Privileges Required
UI
None
User Interaction
VC
High
Confidentiality (Vulnerable System)
VI
None
Integrity (Vulnerable System)
VA
None
Availability (Vulnerable System)
SC
None
Confidentiality (Subsequent System)
SI
None
Integrity (Subsequent System)
SA
None
Availability (Subsequent System)
Affected
- Vendor
- broadcom
- Product
- rabbitmq server
Versions
- >= 3.13.0, < 3.13.18
- >= 4.0.0, < 4.0.23
- >= 4.1.0, < 4.1.14
- >= 4.2.0, < 4.2.9
- >= 4.3.0, < 4.3.3
Stated as the source expressed them.
References
- patchPatchhttps://github.com/rabbitmq/rabbitmq-server/commit/a7528314840c4f8dc9904684f9f97ffa7aac6349
- patchPatchhttps://github.com/rabbitmq/rabbitmq-server/commit/edbead0eabbd65925d0dc914a22d6a29e155e646
- advisoryRelease Noteshttps://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.9
- advisoryRelease Noteshttps://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.3.3
- vendorExploithttps://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-4r6f-9cpw-f6g6
Related threats
same CWE or vendorCVE-2026-107782 — System Informer before 4.0.26241.138 contains an incorrect authorization vulnerability in the phsvc helper that allows local attackers to reach pri…
CVE-2026-107782 · 2h ago
CVE-2026-107706 — Dolibarr ERP CRM before 24.0.2 contains an incorrect authorization vulnerability in htdocs/core/ajax/updateextrafield.php that checks only read per…
CVE-2026-107706 · 3h ago
CVE-2026-97147 — In OpenStack Mistral through 23.0.0, several of the v2 API write paths resolve the target object with a query that can return another project's res…
CVE-2026-97147 · 5h ago
CVE-2026-93861 — In OpenStack Mistral through 23.0.0, the workflow membership API lets a project that has accepted a share of another project's private workflow cre…
CVE-2026-93861 · 5h ago
CVE-2026-107336 — Malcolm's front nginx reverse proxy defines a "Dashboards → Arkime shortcut" location using a case-insensitive regex matcher but a case-sensitive r…
CVE-2026-107336 · 5h ago
CVE-2026-107334 — Malcolm's nginx Lua role-based access control (RBAC) layer decides whether an authenticated user may reach a role-restricted path (e.g.
CVE-2026-107334 · 5h ago