CVE-2026-57217EPSS p26.6%
CVE-2026-57217CVE-2026-57217
broadcom / rabbitmq_server
Description
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ topic authorization can allow restricted topic writes and binds during metadata-store failures because topic-permission lookup errors from Khepri can collapse to undefined, which the internal backend treats as allow. This issue is fixed in versions 3.13.15, 4.0.21, 4.1.11, and 4.2.6.
Scoring
| CVSS | 6.5 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 0.35% probability of exploitation · percentile 26.6% · 2026-10-05T12:00:23Z |
| Last modified | 2026-07-13 |