CVE-2026-67233
Description
A flaw was found in RabbitMQ. An authenticated monitoring user, who is intended to have read-only access, can exploit an improper authorization vulnerability. This allows them to delete or restart 'shovels' in any virtual host they can access, leading to a denial of service or disruption of message routing.
Statement
Red Hat rates this flaw Moderate. To exploit it, an attacker needs broker credentials with the monitoring tag and network access to the management HTTP listener, and the broker must have the rabbitmq_shovel and rabbitmq_shovel_management plugins enabled. The monitoring role check has no per-vhost scope, so one monitoring account can delete or restart shovels in every virtual host on the broker, including vhosts where it holds no permissions. The attacker gains no read access and cannot create or modify shovels. The broker and unrelated clients keep running; the impact is limited to message flow through the targeted shovels until an administrator recreates them. An attacker who keeps the credentials can repeat the deletion, so rotating or removing the account should come before restoring the shovels.
Mitigation
Disable the shovel management extension on brokers that do not need to manage shovels over HTTP. Enable rabbitmq_shovel explicitly first so it stays active if it was only pulled in as a dependency:
rabbitmq-plugins enable rabbitmq_shovel
rabbitmq-plugins disable rabbitmq_shovel_management
This removes the /api/shovels endpoint. Accounts with the policymaker or administrator tag can still delete shovels through /api/parameters, which enforces the correct role check. If the endpoint has to stay available, remove the monitoring tag from any account that should not be able to stop message flow.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 7.1 | N/A | N/A |
| Attack Vector | Network | N/A | N/A |
| Attack Complexity | Low | N/A | N/A |
| Privileges Required | Low | N/A | N/A |
| User Interaction | None | N/A | N/A |
| Scope | Unchanged | N/A | N/A |
| Confidentiality | None | N/A | N/A |
| Integrity Impact | High | N/A | N/A |
| Availability Impact | Low | N/A | N/A |
Vector
Red Hat: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Understanding the Weakness (CWE)
Access Control
Technical Impact: Gain Privileges or Assume Identity
A user can access restricted functionality and/or sensitive information that may include administrative functionality and user accounts.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.