Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2026-57217

RabbitMQ topic authorization allows restricted writes when a Khepri lookup fails

Technology

RabbitMQ

CVSS Score

6.5 / 10.0

Affected Versions

3.13.0 to 3.13.14; 4.0.0 to 4.0.20; 4.1.0 to 4.1.10; 4.2.0 to 4.2.5

Upstream Fix

4.2.6 (public); 3.13.15, 4.0.21, 4.1.11 (commercial)

Published

July 10, 2026

OSSeva Coverage

Fixed upstream

Description

During metadata store failures, topic permission lookup errors from Khepri could collapse to undefined, which the internal authorization backend treated as allow, so restricted topic writes and binds could go through, including across tenants sharing a broker. Fixed in 4.2.6 and in the commercial 3.13.15, 4.0.21 and 4.1.11.

Upstream record: NVD · CVE.org

Is your RabbitMQ deployment affected?

If you're running 3.13.0 to 3.13.14; 4.0.0 to 4.0.20; 4.1.0 to 4.1.10; 4.2.0 to 4.2.5, you need this patch. Book a discovery call to get covered.