Junglewise Threat Intelligence

CVE-2026-57217: RabbitMQ incorrect authorization in topic permissions during metadata-store failure

CVE-2026-57217 · Severity: info · CVSS 7 · Published 2026-07-10

Vendors: RabbitMQ.

Executive brief

RabbitMQ is a widely used messaging broker that facilitates communication between different software applications. A security flaw has been identified where the system may fail to properly enforce access restrictions on specific message topics during internal database failures. This could allow a user with limited access to write to or interact with restricted data channels they should not be able to reach, potentially compromising the integrity of business communications.

Technical details

An incorrect authorization vulnerability exists in RabbitMQ's topic-permission logic. When the Khepri metadata store encounters a lookup error, the system may collapse the error state to 'undefined'. The internal backend incorrectly interprets this 'undefined' state as an 'allow' instruction rather than a 'deny'. An authenticated attacker with network access to the broker can exploit this during metadata-store failures to perform unauthorized topic writes and binds. The issue is resolved by distinguishing between missing keys and lookup errors to ensure a fail-closed posture.

Affected products

  • RabbitMQ RabbitMQ Server >= 3.13.0, < 3.13.15; >= 4.0.0, < 4.0.21; >= 4.1.0, < 4.1.11; >= 4.2.0, < 4.2.6

Timeline

  • 2026-04-06: patched: Fixes merged into main and backported to stable branches.
  • 2026-04-23: advisory: Release of version 4.2.6 containing the fix.
  • 2026-07-10: disclosed: CVE-2026-57217 published.

References