Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-67231: RabbitMQ may accept fake client certificates

CVE-2026-67231 · published 16 days ago
Summary

RabbitMQ servers that run the trust‑store plug‑in on older versions can be tricked into trusting a fabricated certificate if an attacker knows the issuer name and serial number of a approved certificate. This lets an unauthorized user connect as a trusted client. Upgrade to the latest RabbitMQ release or disable the vulnerable plug‑in to close the gap.

What to do
  • Update debian rabbitmq-server to version 4.3.0-2.
  • Update rabbitmq to version 4.2.6.
Affected software
Ecosystem VendorProductAffected versions
– rabbitmq rabbitmq-server >= 3.13.0, < 3.13.15
Ubuntu:Pro:16.04:LTS canonical rabbitmq-server All versions
Debian:12 debian rabbitmq-server All versions
Debian:14 debian rabbitmq-server < 4.3.0-2
Fix: upgrade to 4.3.0-2
Bitnami – rabbitmq >= 4.2.0, < 4.2.6
Fix: upgrade to 4.2.6
Original advisory text
RabbitMQ: Trust-store whitelist by Issuer+Serial only
RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The trust-store plugin installs a verify_fun that overrides {bad_cert, unknown_ca} / {bad_cert, selfsigned_peer} when the presented cert "matches" a whitelisted one. The match key is extract_issuer_id/1 → public_key:pkix_issuer_id/2 → {IssuerName, SerialNumber} , both fields are taken verbatim from the presented certificate body and contain no public-key, SKI, fingerprint or signature material. is_whitelisted/1 is a pure ets:member lookup; the stored full DER is used only for list/0 display and is never compared against the presented cert. cacerts is [], so the whitelisted cert is never used as a trust anchor for path validation either. TLS client-authentication bypass: an attacker who knows the issuer DN + serial of any whitelisted certificate can connect with a forged self-signed cert. Preconditions include rabbitmq_trust_store plugin enabled and used as the TLS verify_fun Attacker knows or can guess the {Issuer, Serial} of at least one whitelisted cert (non-secret; exposed via CLI/logs/any cert copy). This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0.
Fix within
Internet-facing 14 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker partial control
Severity
9.1 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-295Improper Certificate Validation
Timeline
Published23 Sep 2026
Updated7 Oct 2026
First seen23 Sep 2026
Track software like this
Free during beta