{"cve":"CVE-2026-66076","enrichment":{"affected":[{"configurations":[{"platform":null,"status":"affected","versions":{"scheme":"semver","value":"[3.13.0,3.13.15)"}},{"platform":null,"status":"affected","versions":{"scheme":"semver","value":"[4.0.0,4.0.20)"}},{"platform":null,"status":"affected","versions":{"scheme":"semver","value":"[4.1.0,4.1.11)"}},{"platform":null,"status":"affected","versions":{"scheme":"semver","value":"[4.2.0,4.2.6)"}}],"enrichment":{"confidence":100.0,"confidence_source":"matching","scores":[{"score":100.0,"source":"matching"}]},"original":{"product":"rabbitmq-server","source":"cna","vendor":"rabbitmq"},"product":"rabbitmq-server","vendor":"rabbitmq"}],"created":"2026-09-23T21:30:07.279995+00:00","updated":"2026-09-23T22:00:14.681016+00:00","vendors":["rabbitmq","rabbitmq$PRODUCT$rabbitmq-server"]},"mitre":{"cpes":[],"created":"2026-09-23T19:57:11.906000+00:00","description":"RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, is_authorized/2 calls rabbit_mgmt_util:is_authorized/2, which checks only the management tag, instead of is_authorized_vhost/2. The /api/queues/quorum/:vhost/:queue/status handler reads the vhost from the path without checking that the user can access it. Any management-tagged user can therefore read Raft status, including leader, members, term, and commit index, for quorum queues in inaccessible vhosts, exposing cross-tenant queue names and cluster topology. The management plugin must be enabled and the attacker must have a management tag. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{"score":2.3,"vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}},"mitre_repo_path":"cves/2026/66xxx/CVE-2026-66076.json","references":["https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6","https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-j45q-v7g2-82ph"],"title":"RabbitMQ: Cross-vhost quorum-queue status and stream tracking disclosure","updated":"2026-09-23T19:57:11.906000+00:00","vendors":[],"weaknesses":["CWE-862"]},"nvd":{"cpes":[],"created":"2026-09-23T20:17:13.007000+00:00","description":"RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, is_authorized/2 calls rabbit_mgmt_util:is_authorized/2, which checks only the management tag, instead of is_authorized_vhost/2. The /api/queues/quorum/:vhost/:queue/status handler reads the vhost from the path without checking that the user can access it. Any management-tagged user can therefore read Raft status, including leader, members, term, and commit index, for quorum queues in inaccessible vhosts, exposing cross-tenant queue names and cluster topology. The management plugin must be enabled and the attacker must have a management tag. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{"score":2.3,"vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}},"nvd_repo_path":"2026/CVE-2026-66076.json","references":["https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6","https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-j45q-v7g2-82ph"],"title":null,"updated":"2026-09-23T20:17:13.007000+00:00","vendors":[],"weaknesses":["CWE-862"]},"opencve":{"changes":[{"created":"2026-09-23T20:15:00+00:00","data":[{"details":{"new":"RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, is_authorized/2 calls rabbit_mgmt_util:is_authorized/2, which checks only the management tag, instead of is_authorized_vhost/2. The /api/queues/quorum/:vhost/:queue/status handler reads the vhost from the path without checking that the user can access it. Any management-tagged user can therefore read Raft status, including leader, members, term, and commit index, for quorum queues in inaccessible vhosts, exposing cross-tenant queue names and cluster topology. The management plugin must be enabled and the attacker must have a management tag. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0.","old":null},"type":"description"},{"details":{"new":"RabbitMQ: Cross-vhost quorum-queue status and stream tracking disclosure","old":null},"type":"title"},{"details":{"added":["CWE-862"],"removed":[]},"type":"weaknesses"},{"details":{"added":["https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6","https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-j45q-v7g2-82ph"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV4_0":{"score":2.3,"vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"09faf434-110e-49bf-a8cb-0d9486203439"},{"created":"2026-09-23T22:15:00+00:00","data":[{"details":["rabbitmq","rabbitmq$PRODUCT$rabbitmq-server"],"type":"first_time"},{"details":{"added":["rabbitmq","rabbitmq$PRODUCT$rabbitmq-server"],"removed":[]},"type":"vendors"}],"id":"6c1601b2-02ae-4fc7-a38b-b516d6ccb311"}],"cpes":{"data":[],"providers":[]},"created":{"data":"2026-09-23T19:57:11.906000+00:00","provider":"mitre"},"description":{"data":"RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, is_authorized/2 calls rabbit_mgmt_util:is_authorized/2, which checks only the management tag, instead of is_authorized_vhost/2. The /api/queues/quorum/:vhost/:queue/status handler reads the vhost from the path without checking that the user can access it. Any management-tagged user can therefore read Raft status, including leader, members, term, and commit index, for quorum queues in inaccessible vhosts, exposing cross-tenant queue names and cluster topology. The management plugin must be enabled and the attacker must have a management tag. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{},"provider":null},"cvssV4_0":{"data":{"score":2.3,"vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"},"provider":"mitre"},"epss":{"data":{},"provider":null},"kev":{"data":{},"provider":null},"ssvc":{"data":{},"provider":null},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6","https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-j45q-v7g2-82ph"],"providers":["mitre","nvd"]},"title":{"data":"RabbitMQ: Cross-vhost quorum-queue status and stream tracking disclosure","provider":"mitre"},"updated":{"data":"2026-09-23T22:00:14.681016+00:00","provider":"enrichment"},"vendors":{"data":["rabbitmq","rabbitmq$PRODUCT$rabbitmq-server"],"providers":["enrichment"]},"weaknesses":{"data":["CWE-862"],"providers":["mitre","nvd"]}}}