Back

LOW

RabbitMQ: Cross-vhost quorum-queue status and stream tracking disclosure

Published Sep 23, 2026

Description

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, is_authorized/2 calls rabbit_mgmt_util:is_authorized/2, which checks only the management tag, instead of is_authorized_vhost/2. The /api/queues/quorum/:vhost/:queue/status handler reads the vhost from the path without checking that the user can access it. Any management-tagged user can therefore read Raft status, including leader, members, term, and commit index, for quorum queues in inaccessible vhosts, exposing cross-tenant queue names and cluster topology. The management plugin must be enabled and the attacker must have a management tag. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0.

Affected products

Remediation

No remediation recorded yet.

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Sep 23, 2026
Updated Sep 24, 2026
Reserved Jul 23, 2026
CISA Vulnrichment
Updated Sep 24, 2026
NVD
Status Received
Modified Sep 23, 2026
Red Hat
Severity Moderate
Public date Sep 23, 2026
ENISA EUVD
Assigner GitHub_M
Published Sep 23, 2026
Updated Sep 24, 2026
Exploited since n/a
EUVD-2026-85623