BIT-rabbitmq-2026-66075

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/rabbitmq/BIT-rabbitmq-2026-66075.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-rabbitmq-2026-66075
Aliases
Published
2026-10-01T09:32:52Z
Modified
2026-10-01T10:11:13Z
Summary
RabbitMQ: Monitoring-tag user can restart federation links
Details

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, is_authorized/2 for the /federation-links/.../restart route uses is_authorized_monitor (accepts the monitoring tag), while allowed_methods permits DELETE and delete_resource/2 triggers rabbit_federation_link_sup:restart. There is no per-method elevation check and no comment marking it intentional. A read-only monitoring user can restart any federation link , a state-changing operation that disrupts message flow. Preconditions include rabbitmq_federation + rabbitmq_federation_management plugins enabled Attacker has credentials with the monitoring tag. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1.

Database specific
{
    "cpes":  [
        "cpe:2.3:a:vmware:rabbitmq:*:*:*:*:*:*:*:*"
    ],
    "severity":  "Low"
}
References

Affected packages

Bitnami / rabbitmq

Package

Name
rabbitmq
Purl
pkg:bitnami/rabbitmq

Severity

  • 2.3 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
3.13.0
Fixed
3.13.15
Introduced
4.0.0
Fixed
4.0.20
Introduced
4.1.0
Fixed
4.1.11
Introduced
4.2.0
Fixed
4.2.6
Introduced
4.3.0
Fixed
4.3.1

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/rabbitmq/BIT-rabbitmq-2026-66075.json"