CVE-2026-25767 PUBLISHED

LavinMQ has incomplete shovel configuration validation

Assigner: GitHub_M
Reserved: 05.02.2026 Published: 12.02.2026 Updated: 12.02.2026

LavinMQ is a high-performance message queue & streaming server. Before 2.6.8, an authenticated user, with the “Policymaker” tag, could create shovels bypassing access controls. an authenticated user with the "Policymaker" management tag could exploit it to read messages from vhosts they are not authorized to access or publish messages to vhosts they are not authorized to access. This vulnerability is fixed in 2.6.8.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.6

Product Status

Vendor cloudamqp
Product lavinmq
Versions
  • Version < 2.6.8 is affected

References

Problem Types

  • CWE-863: Incorrect Authorization CWE