Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3191 articles · 168085 vulns · 37/41 feeds (7d)
← Back to list
0.0
CVE-2026-44838EXPLOITEDPATCHED
broadcom · rabbitmq_server

RabbitMQ MQTT Topic Permission Authorization Bypass

Description

RabbitMQ is a messaging and streaming broker. From 4.2.0 to before 4.2.4, RabbitMQ's MQTT plugin allows for topic-level authorization using regular expressions with variable substitution. Administrators can create patterns such as ^{client_id}-sensors$ to restrict user access to topics that include their client ID. However, the client_id is provided by the user in the MQTT CONNECT packet and is inserted into the regex pattern without escaping special regex characters. This flaw enables an authenticated MQTT user to inject regex operators to bypass authorization. This vulnerability is fixed in 4.2.4 and 4.3.0.

Affected Products

VendorProductVersions
broadcomrabbitmq_server>= 4.2.0, < 4.2.4

References

  • https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-x866-xp2g-cx8v(x_refsource_CONFIRM)

Related News (3 articles)

Tier B
BSI Advisories9d ago
[NEU] [mittel] RabbitMQ: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB31d ago
CVE-2026-44838 | RabbitMQ rabbitmq-server up to 4.2.3 Regular Expression authorization (GHSA-x866-xp2g-cx8v)
→ No new info (linked only)
Tier B
BSI Advisories51d ago
[NEU] [mittel] RabbitMQ: Mehrere Schwachstellen
→ No new info (linked only)
CVSS 3.10.0 NONE
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
4.2.4
CWECWE-863
PublishedMay 27, 2026
Last enriched31d agov2
Tags
cross-site scriptingsecurity bypassmultiple vulnerabilities
Trending Score12
Source articles3
Independent2
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-40012EXP
Information about ECS zero scoped answers might leak to clients that use a specific ECS
Trending: 54
HIGHCVE-2026-41708EXP
Spring Cloud Sleuth instrumentation of Spring TX DoS vulnerability
Trending: 12
NONECVE-2026-11626
Local Privilege Escalation in Symantec Endpoint Protection macOS CleanWipe Removal Tool
Trending: 5
NONECVE-2026-11815
Insecure Deserialization via MITM in Layer 7 Policy Manager
Trending: 2
CRITICALPRE-CVEEXP
Critical vulnerabilities in VMware Tanzu for Valkey
Trending: 1

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 27, 2026
Discovered by ZDM
May 27, 2026
Updated: description, severity, cvssEstimate, activelyExploited, patchAvailable
May 27, 2026
Actively Exploited
May 28, 2026
Patch Available
May 28, 2026

Version History

v2
Last enriched 31d ago
v2Tier C31d ago

Updated severity to CRITICAL, added new description, and specified patch available in version 4.2.4.

descriptionseveritycvssEstimateactivelyExploitedpatchAvailable
via VulDB
v131d ago

Initial creation