CVE-2026-67223: RabbitMQ: LDAP DN injection via unescaped substitution

Published Sep 25, 2026
·
Updated

RabbitMQ is a messaging and streaming broker. The advisory establishes affected 3.13, 4.0, 4.1, 4.2, and 4.3 maintenance lines but contains conflicting first-fixed versions for the 3.13, 4.0, and 4.1 lines. fill/2 substitutes ${username} into userdnpattern without RFC 4514 DN escaping, allowing a crafted username to alter the LDAP bind DN and potentially select a different directory entry. Exploitation requires rabbitmqauthbackendldap with a userdnpattern containing ${username}, a directory layout in which the injected suffix resolves usefully, and a password valid for the resulting DN. The advisory body identifies 3.13.15, 4.0.20, 4.1.11, 4.2.9, and 4.3.3 as fixed, while structured metadata identifies 3.13.18, 4.0.23, 4.1.14, 4.2.9, and 4.3.3. No fixed-version assertion is certifiable until a curator resolves this conflict.

Affected Software

1 affected component
RabbitMQ RabbitMQ

Event History

Sep 25, 2026
CVE Published
via MITRE·04:15 PM
Data Sourced
via MITRE·04:15 PM
DescriptionWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Exposure requires RabbitMQ to use rabbitmq_auth_backend_ldap and to configure user_dn_pattern with the ${username} placeholder. Deployments without that LDAP authentication configuration are not described as affected.

2

What must an attacker have to exploit it?

The attacker needs a crafted username that changes the resulting LDAP bind DN, a directory layout where the injected suffix resolves to a useful entry, and a valid password for that resulting DN. The issue does not by itself bypass password validation.

3

How can I assess whether our LDAP configuration is at risk?

Inspect the RabbitMQ LDAP authentication configuration for user_dn_pattern values containing ${username}. Then determine whether special DN characters in a supplied username could alter the intended bind DN into another resolvable directory entry.

4

Can a fixed version be selected confidently from the advisory?

No. The advisory body and structured metadata disagree for the 3.13, 4.0, and 4.1 maintenance lines; only 4.2.9 and 4.3.3 are consistent between both sources. The version conflict must be resolved before asserting a fixed version for the other lines.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203