{"id":"CVE-2026-66067","title":"RabbitMQ is a messaging and streaming broker","summary":"RabbitMQ is a messaging and streaming broker. Prior to versions 4.2.7 and 4.3.1, The stream open handler calls only check_vhost_access; it omits the node/vhost/user connection-limit checks that rabbit_reader performs for AMQP. A develope…","severity":"medium","cvss":6,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","cwe":["CWE-770","CWE-1220"],"vendor":"rabbitmq","product":"rabbitmq-server","affected":["rabbitmq-server >= 4.2.0, < 4.2.7","rabbitmq-server >= 4.3.0, < 4.3.1"],"published":"2026-09-23","updated":"2026-09-23","sourceUpdated":"2026-09-23T21:16:58.783","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-66067","references":[{"url":"https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.7","label":"security-advisories@github.com"},{"url":"https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.3.1","label":"security-advisories@github.com"},{"url":"https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-hwqx-2gfg-89qf","label":"security-advisories@github.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-66067.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-66067"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2539766"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-66067"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-66067"},{"url":"https://access.redhat.com/errata/RHSA-2026:67552"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"cvssSource":"cna","ingestedAt":"2026-09-23T20:32:10.760Z","patched":["hardened_images"],"scores":{"cna":6,"vendor":6.5},"slug":"CVE-2026-66067","body":"## Overview\n\nRabbitMQ is a messaging and streaming broker. Prior to versions 4.2.7 and 4.3.1, The stream open handler calls only check_vhost_access; it omits the node/vhost/user connection-limit checks that rabbit_reader performs for AMQP. A developer %% FIXME comment at the cited line explicitly acknowledges the gap. No compensating enforcement exists in connection tracking or elsewhere in rabbitmq_stream. An authenticated tenant can fully bypass operator-configured per-user and per-vhost connection caps by connecting via port 5552 instead of 5672. Preconditions include rabbitmq_stream plugin enabled Authenticated stream-protocol credentials Operator relies on per-user/per-vhost connection limits for tenant isolation. This issue is fixed in versions 4.2.7 and 4.3.1.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **RHSA-2026:67552** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67552)\n- **Red Hat VEX** · Moderate · affected: Red Hat Hardened Images · no fix planned: Red Hat Hardened Images · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-66067.json)","depth":"sunlit","depthScore":33,"depthScoreParts":{"impact":33,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}