EXPOSURES › CVE-2026-57211
CVE-2026-57211
MEDIUMRabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path validation when multiple management extensio
▸ RECOMMENDED ACTION Patch the affected products and confirm your instances are covered.
RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path validation when multiple management extension plugins are enabled, causing outbound DNS and SMB requests to attacker-controlled UNC paths. This issue is fixed in versions 4.1.11 and 4.2.6.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Clarity Broadcom |
Authorized |
| General Support Systems (GSS) Broadcom |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |
| Rally Broadcom |
Authorized |
| Symantec Gov Cloud Security (GCS) Broadcom |
In Process |