OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-67412

HIGH · CVSS 7.1 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

RabbitMQ versions from 3.13.0 to 4.3.3, including several prior releases, are vulnerable due to a flaw in the Federation upstream feature that bypasses virtual host (vhost) authorization, allowing a policymaker on one vhost to read and drain messages from another vhost without proper permissions. This can lead to unauthorized data access and loss, as the default acknowledgment mode results in the source messages being deleted rather than copied. Organizations using affected RabbitMQ versions, particularly those managing sensitive or multi-tenant environments, should prioritize upgrading to the patched versions to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-67412
Severity
HIGH
CVSS
7.1
EPSS
0.30%

Original NVD Description

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 4.3.3, 4.2.9 , 4.1.14, 4.0.24, and 3.13.18, Federation upstream in RabbitMQ skips vhost authorization allowing cross-vhost message access. what the bug lets you do. A policymaker on one vhost reads and drains messages out of another vhost it has no permission on. With the default ack-mode the source messages are consumed (deleted), not copied. Why that should not 1. Federation validates the upstream URI without any vhost-access Cross-vhost message read/drain from a per-vhost policymaker, breaking vhost tenancy This issue is fixed in versions 4.3.3, 4.2.9 , 4.1.14, 4.0.24, and 3.13.18.

Related CVEs

Other vulnerabilities affecting the same vendor(s)