Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-44838

RabbitMQ MQTT topic authorization bypass through regex injection in the client ID

Technology

RabbitMQ

CVSS Score

8.1 / 10.0

Affected Versions

4.2.0 to 4.2.3

Upstream Fix

4.2.4; 4.3.0

Published

May 27, 2026

OSSeva Coverage

Fixed upstream

Description

The MQTT plugin supports topic authorization with regular expressions that substitute variables such as the client ID, for example ^{client_id}-sensors$. The client ID comes from the MQTT CONNECT packet and was inserted into the pattern without escaping regex characters, so an authenticated MQTT user could inject regex operators and reach topics the pattern was meant to deny. Fixed in 4.2.4 and 4.3.0. CVE-2026-67407 later completed the escaping.

Upstream record: NVD · CVE.org

Is your RabbitMQ deployment affected?

If you're running 4.2.0 to 4.2.3, you need this patch. Book a discovery call to get covered.