---
id: CVE-2026-57217
title: RabbitMQ is a messaging and streaming broker
summary: >-
  RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21,
  4.1.11, and 4.2.6, RabbitMQ topic authorization can allow restricted topic
  writes and binds during metadata-store failures because topic-permission
  lookup errors fro…
severity: none
cwe:
  - CWE-863
published: '2026-07-10'
updated: '2026-07-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-57217'
references:
  - url: >-
      https://github.com/rabbitmq/rabbitmq-server/commit/94f1d33a70fcfa09006649599e79fc92786a2d36
    label: security-advisories@github.com
  - url: >-
      https://github.com/rabbitmq/rabbitmq-server/commit/ce1f682aa6b398820c5e3ce1ff7435184027c82c
    label: security-advisories@github.com
  - url: 'https://github.com/rabbitmq/rabbitmq-server/pull/15941'
    label: security-advisories@github.com
  - url: 'https://github.com/rabbitmq/rabbitmq-server/pull/15943'
    label: security-advisories@github.com
  - url: 'https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6'
    label: security-advisories@github.com
  - url: >-
      https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-gpvw-75h5-3wvx
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00565
epssPercentile: 0.44533
ingestedAt: '2026-07-11T20:15:27.287Z'
---

## Overview

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ topic authorization can allow restricted topic writes and binds during metadata-store failures because topic-permission lookup errors from Khepri can collapse to undefined, which the internal backend treats as allow. This issue is fixed in versions 3.13.15, 4.0.21, 4.1.11, and 4.2.6.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
