Unrated severityNVD Advisory· Published Feb 12, 2026· Updated Feb 12, 2026
LavinMQ is missing vhost access control
CVE-2026-25768
Description
LavinMQ is a high-performance message queue & streaming server. Before 2.6.6, an authenticated user could access metadata in the broker they should not have access to. This vulnerability is fixed in 2.6.6.
Affected products
2- cloudamqp/lavinmqv5Range: < 2.6.6
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/cloudamqp/lavinmq/commit/e871f8d0a53685f04e39e6410a2421c1f82803b0mitrex_refsource_MISC
- github.com/cloudamqp/lavinmq/pull/1669mitrex_refsource_MISC
- github.com/cloudamqp/lavinmq/security/advisories/GHSA-r2mh-8vq6-qf7mmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.