CVE-2026-57217
RabbitMQ topic authorization allows restricted writes when a Khepri lookup fails
Technology
RabbitMQ
CVSS Score
6.5 / 10.0
Affected Versions
3.13.0 to 3.13.14; 4.0.0 to 4.0.20; 4.1.0 to 4.1.10; 4.2.0 to 4.2.5
Upstream Fix
4.2.6 (public); 3.13.15, 4.0.21, 4.1.11 (commercial)
Published
July 10, 2026
OSSeva Coverage
Fixed upstream
Description
During metadata store failures, topic permission lookup errors from Khepri could collapse to undefined, which the internal authorization backend treated as allow, so restricted topic writes and binds could go through, including across tenants sharing a broker. Fixed in 4.2.6 and in the commercial 3.13.15, 4.0.21 and 4.1.11.
Is your RabbitMQ deployment affected?
If you're running 3.13.0 to 3.13.14; 4.0.0 to 4.0.20; 4.1.0 to 4.1.10; 4.2.0 to 4.2.5, you need this patch. Book a discovery call to get covered.