RabbitMQ: Cross-vhost quorum-queue status and stream tracking disclosure
Published Sep 23, 2026
2.3
LOWCVSS 4.0
EPSS 0.27%
Description
RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, is_authorized/2 calls rabbit_mgmt_util:is_authorized/2, which checks only the management tag, instead of is_authorized_vhost/2. The /api/queues/quorum/:vhost/:queue/status handler reads the vhost from the path without checking that the user can access it. Any management-tagged user can therefore read Raft status, including leader, members, term, and commit index, for quorum queues in inaccessible vhosts, exposing cross-tenant queue names and cluster topology. The management plugin must be enabled and the attacker must have a management tag. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0.
Affected products
-
- Version >= 3.13.0, < 3.13.15StatusaffectedConstraints-
- Version >= 4.0.0, < 4.0.20StatusaffectedConstraints-
- Version >= 4.1.0, < 4.1.11StatusaffectedConstraints-
- Version >= 4.2.0, < 4.2.6StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Rabbitmq | Rabbitmq-Server | n/a |
|
No data.
No data.
Red Hat Hardened Images
rabbitmq-server4-3-main-4.3.6-1.hum1
Fixed · RHSA-2026:67552
Red Hat Hardened Images
rabbitmq-server4.2
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Hardened Images | rabbitmq-server4-3-main-4.3.6-1.hum1 | Fixed | RHSA-2026:67552 |
| Red Hat Hardened Images | rabbitmq-server4.2 | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (7)
- https://access.redhat.com/security/cve/CVE-2026-66076 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2539721 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-85623 Advisory
- https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6 x_refsource_MISC
- https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-j45q-v7g2-82ph exploitx_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-66076
- https://www.cve.org/CVERecord?id=CVE-2026-66076
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-66076 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2539721 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-85623 | Advisory | |
| https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6 | x_refsource_MISC | |
| https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-j45q-v7g2-82ph | exploitx_refsource_CONFIRM | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-66076 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-66076 |
Change history (0)
No recorded changes yet.