CVE-2026-44838
RabbitMQ MQTT topic authorization bypass through regex injection in the client ID
Technology
RabbitMQ
CVSS Score
8.1 / 10.0
Affected Versions
4.2.0 to 4.2.3
Upstream Fix
4.2.4; 4.3.0
Published
May 27, 2026
OSSeva Coverage
Fixed upstream
Description
The MQTT plugin supports topic authorization with regular expressions that substitute variables such as the client ID, for example ^{client_id}-sensors$. The client ID comes from the MQTT CONNECT packet and was inserted into the pattern without escaping regex characters, so an authenticated MQTT user could inject regex operators and reach topics the pattern was meant to deny. Fixed in 4.2.4 and 4.3.0. CVE-2026-67407 later completed the escaping.
Is your RabbitMQ deployment affected?
If you're running 4.2.0 to 4.2.3, you need this patch. Book a discovery call to get covered.