CVE-2026-67233Medium· 6.0▾ SunlitRabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, The shovel management resource's is_authorized/2 delegates to rabbit_mgmt_util:is_authorized_monitor/2, which accepts the monitori…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 33 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, The shovel management resource's is_authorized/2 delegates to rabbit_mgmt_util:is_authorized_monitor/2, which accepts the monitoring tag. But allowed_methods includes DELETE, and delete_resource/2 deletes / restarts shovel runtime parameters with no additional role check. A monitoring user , intended to have read-only visibility , can therefore delete or restart any shovel in any vhost they can see. A read-only monitoring user can delete or restart any dynamic shovel , a state-changing operation that the equivalent /api/parameters endpoint correctly restricts to policymaker. Preconditions include rabbitmq_shovel + rabbitmq_shovel_management plugins enabled Attacker has credentials with the monitoring tag. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-66075Low· 2.3RabbitMQ is a messaging and streaming broker
CVE-2026-67218Low· 2.1RabbitMQ is a messaging and streaming broker
CVE-2026-66072Medium· 6.0RabbitMQ is a messaging and streaming broker
CVE-2026-67224Low· 2.1RabbitMQ is a messaging and streaming broker
CVE-2026-66076Low· 2.3RabbitMQ is a messaging and streaming broker
CVE-2026-67405Medium· 5.3RabbitMQ is a messaging and streaming broker