CVE-2026-66078 | RabbitMQ prior 3.13.15/4.0.20/4.1.11/4.2.6 Bulk Delete /api/users/bulk-delete rabbitauthbackendinternal:deleteuser access control
A vulnerability was found in RabbitMQ prior 3.13.15/4.0.20/4.1.11/4.2.6. It has been rated as problematic. This vulnerability affects the function rabbitauthbackendinternal:deleteuser of the file /api/users/bulk-delete of the component Bulk Delete. This manipulation causes improper access controls.
This vulnerability is tracked as CVE-2026-66078. The attack is possible to be carried out remotely. No exploit exists.VulDB Recent EntriesRead More