CVE-2026-57217: RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypass
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ topic authorization can allow restricted topic writes and binds during metadata-store failures because topic-permission lookup errors from Khepri can collapse to undefined, which the internal backend treats as allow. This issue is fixed in versions 3.13.15, 4.0.21, 4.1.11, and 4.2.6.
Other sources
RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypass
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.13.7-7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.13.15 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.0.21 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.1.11 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.2.6
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57217?
CVE-2026-57217 has a severity level of high with a CVSS score of 7.
How do I fix CVE-2026-57217?
You can fix CVE-2026-57217 by applying the available patches provided in the latest RabbitMQ releases.
What type of vulnerability is CVE-2026-57217?
CVE-2026-57217 is a cross-tenant routing-key bypass vulnerability in RabbitMQ.
Which versions of RabbitMQ are affected by CVE-2026-57217?
CVE-2026-57217 affects RabbitMQ versions prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6.
Is CVE-2026-57217 a local or remote vulnerability?
CVE-2026-57217 is a network vulnerability that can be exploited remotely.