Back

LOW

RabbitMQ: Monitoring-tag DELETE of auth-attempt metrics

Published Sep 23, 2026

Description

RabbitMQ is a messaging and streaming broker. Prior to versions 4.1.13, 4.2.7, and 4.3.0, is_authorized/2 uses is_authorized_monitor for all methods. DELETE resets rabbit_core_metrics:reset_auth_attempt_metrics(). Impact is cosmetic (counters only, no log erasure), but inconsistent with rabbit_mgmt_wm_reset.erl which requires admin for the analogous operation. A monitoring-tagged user can reset the per-node authentication-attempt counters via DELETE /api/auth/attempts/:node, erasing evidence of brute-force activity. The sibling endpoint wm_reset requires administrator. Preconditions include Management plugin enabled monitoring tag. This issue is fixed in versions 4.1.13, 4.2.7, and 4.3.0.

Affected products

Remediation

Red Hat statement

Red Hat rates this flaw MODERATE in products that ship affected RabbitMQ builds. A monitoring-tagged user can reset authentication-attempt counters through the Management API without administrator permission. Broker logs remain intact, so the impact is limited to tampering with security metrics.

Red Hat mitigation

Restrict Management API access and monitoring-tag accounts, or disable the Management plugin where it is not needed.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Sep 23, 2026
Updated Sep 24, 2026
Reserved Jul 23, 2026
CISA Vulnrichment
Updated Sep 24, 2026
NVD
Status Received
Modified Sep 23, 2026
Red Hat
Severity Moderate
Public date Sep 23, 2026
ENISA EUVD
Assigner GitHub_M
Published Sep 23, 2026
Updated Sep 24, 2026
Exploited since n/a
EUVD-2026-85632