CVE-2026-66076 | RabbitMQ up to 4.3.x Management Plugin status is_authorized vhost information disclosure

SecurityVulns

A vulnerability was found in RabbitMQ up to 3.13.14/4.0.19/4.1.10/4.2.5/4.3.x and classified as problematic. Affected is the function is_authorized of the file /api/queues/quorum/:vhost/:queue/status of the component Management Plugin. Executing a manipulation of the argument vhost can lead to information disclosure.

This vulnerability is registered as CVE-2026-66076. It is possible to launch the attack remotely. No exploit is available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More