Aller au contenu

Fiche vulnérabilité

CVE-2026-25767 : faille élevée 84codes lavinmq (CVSS 8.1)

Description

LavinMQ is a high-performance message queue & streaming server. Before 2.6.8, an authenticated user, with the “Policymaker” tag, could create shovels bypassing access controls. an authenticated user with the "Policymaker" management tag could exploit it to read messages from vhosts they are not authorized to access or publish messages to vhosts they are not authorized to access. This vulnerability is fixed in 2.6.8.

En bref

Sévérité
Élevée (CVSS 8.1)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Exploitation active
Non signalée par la CISA
Publication
12 févr. 2026
Dernière mise à jour
17 juin 2026

Produits concernés

  • 84codes lavinmq

Références

Rechercher une autre vulnérabilité dans la base CVE