Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4508 articles · 223853 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-57217EXPLOITED
broadcom · rabbitmq_server

RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypass

Description

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ topic authorization can allow restricted topic writes and binds during metadata-store failures because topic-permission lookup errors from Khepri can collapse to undefined, which the internal backend treats as allow. This issue is fixed in versions 3.13.15, 4.0.21, 4.1.11, and 4.2.6.

Affected Products

VendorProductVersions
broadcomrabbitmq_server>= 4.2.0, < 4.2.6, >= 4.1.0, < 4.1.11, >= 4.0.0, < 4.0.21, >= 3.13.0, < 3.13.15

References

  • https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-gpvw-75h5-3wvx(x_refsource_CONFIRM)
  • https://github.com/rabbitmq/rabbitmq-server/pull/15941(x_refsource_MISC)
  • https://github.com/rabbitmq/rabbitmq-server/pull/15943(x_refsource_MISC)
  • https://github.com/rabbitmq/rabbitmq-server/commit/94f1d33a70fcfa09006649599e79fc92786a2d36(x_refsource_MISC)
  • https://github.com/rabbitmq/rabbitmq-server/commit/ce1f682aa6b398820c5e3ce1ff7435184027c82c(x_refsource_MISC)
  • https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6(x_refsource_MISC)

Related News (3 articles)

Tier A
Microsoft MSRC74d ago
CVE-2026-57217 RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypass
→ No new info (linked only)
Tier C
VulDB79d ago
CVE-2026-57217 | RabbitMQ up to 3.13.14/4.0.20/4.1.10/4.2.5 Topic Authorization lookup improper authorization
→ No new info (linked only)
Tier B
BSI Advisories94d ago
[NEU] [hoch] RabbitMQ: Mehrere Schwachstellen
→ No new info (linked only)

Discussion (0)

Loading…

CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-863
PublishedJul 10, 2026
Last enriched79d agov2
Tags
CVE-2026-57217
Trending Score0
Source articles3
Independent3
Info Completeness7/14
Missing: cvss, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-57220
RabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoS
Trending: 17
CRITICALPRE-CVE
Multiple vulnerabilities in Broadcom VMware Tanzu Greenplum and RabbitMQ products
NONECVE-2026-15380
Local privilege escalation in Symantec ITMS
CRITICALPRE-CVE
Critical Vulnerabilities in VMware Tanzu for MySQL on Kubernetes
NONECVE-2026-15379
Arbitrary File Read as SYSTEM in Symantec ITMS

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 10, 2026
Discovered by ZDM
Jul 10, 2026
Updated: severity, activelyExploited, tags
Jul 10, 2026
Actively Exploited
Jul 13, 2026

Version History

v2
Last enriched 79d ago
v2Tier C79d ago

Updated severity to CRITICAL, marked as actively exploited, and added new tag CVE-2026-57217.

severityactivelyExploitedtags
via VulDB
v179d ago

Initial creation