CVE-2026-67412 — RabbitMQ is a messaging and streaming broker.
Description
RabbitMQ is a messaging and streaming broker. From 3.13.0 until 4.3.3, 4.2.9 , 4.1.14, 4.0.24, and 3.13.18, Federation upstream in RabbitMQ skips vhost authorization allowing cross-vhost message access. what the bug lets you do. A policymaker on one vhost reads and drains messages out of another vhost it has no permission on. With the default ack-mode the source messages are consumed (deleted), not copied. Why that should not 1. Federation validates the upstream URI without any vhost-access Cross-vhost message read/drain from a per-vhost policymaker, breaking vhost tenancy This issue is fixed in versions 4.3.3, 4.2.9 , 4.1.14, 4.0.24, and 3.13.18.
CVSS v4.0 base metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
AT
Present
Attack Requirements
PR
Low
Privileges Required
UI
None
User Interaction
VC
High
Confidentiality (Vulnerable System)
VI
None
Integrity (Vulnerable System)
VA
None
Availability (Vulnerable System)
SC
Low
Confidentiality (Subsequent System)
SI
None
Integrity (Subsequent System)
SA
None
Availability (Subsequent System)
Affected
- Vendor
- broadcom
- Product
- rabbitmq server
Versions
- >= 3.13.0, < 3.13.18
- >= 4.0.0, < 4.0.24
- >= 4.1.0, < 4.1.14
- >= 4.2.0, < 4.2.9
- >= 4.3.0, < 4.3.3
Stated as the source expressed them.
References
Related threats
same CWE or vendorCVE-2026-107792 — Jivejdon from commit d58a36b0 through commit ee67a65e contains a missing authorization vulnerability in UpdateThreadToForumAction that allows authe…
CVE-2026-107792 · 1h ago
CVE-2026-107725 — Hazelcast is a unified real-time data platform combining stream processing with a fast data store.
CVE-2026-107725 · 1h ago
CVE-2026-107395 — Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask.
CVE-2026-107395 · 3h ago
CVE-2026-93860 — In OpenStack Mistral through 23.0.0, the /v2/maintenance API controller clears the request context and calls the maintenance service directly witho…
CVE-2026-93860 · 5h ago
CVE-2026-12859 — Missing Authorization vulnerability in Caz Informatics Services Trade Inc.
CVE-2026-12859 · 8h ago
CVE-2026-107623 — A flaw was found in the OIDC Dynamic Client Registration (DCR) component of Keycloak.
CVE-2026-107623 · 8h ago