S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Aug 30, 2026

CVE-2026-9133 Scanner

CVE-2026-9133 Scanner - Arbitrary File Read vulnerability in rabbitmq-aws

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3
Times Used
continuous scan runs
6.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-9133
7.7
CVSShigh
Exploitable remotely over the internet · low-privilege account sufficient.

Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws before version 0.2.1. A debug ARN scheme (arn:aws-debug:file) accepted by the PUT /api/aws/arn/validate validation endpoint might allow remote authenticated users to perform arbitrary file reads on any file accessible to the RabbitMQ process. To remediate this issue, customers should upgrade to version 0.2.1 of rabbitmq-aws. If RabbitMQ is configured to use TLS for connections, we also recommend rotating any associated private certificate keys.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
RabbitMQ AWSby AWS
0.1.0
Updated Sep 11, 2026View on NVD →
Detail

rabbitmq-aws is utilized by organizations for integrating RabbitMQ with AWS services. Predominantly, it is deployed in cloud environments where RabbitMQ is used for message brokering. By seamlessly connecting RabbitMQ to various AWS services, it is leveraged by developers to enhance their systems' scalability and efficiency. Companies use it to automate and manage messaging workflows in the cloud. The software's purpose is to facilitate message routing, queuing, and cloud resource management. Routine operations in organizations are streamlined by effectively using RabbitMQ, particularly in deployments involving AWS.

The Arbitrary File Read vulnerability allows authenticated RabbitMQ users to exploit the ARN resolver. Through the management API access, malicious users can input an ARN that prompts the application to read unauthorized files. This vulnerability is serious due to the potential exposure of sensitive data. It highlights a flaw in how file reads are handled, illustrating improper validation processes. Vulnerable configurations are prey to attackers, putting wider system security at risk. Notably, it emphasizes the importance of stringent file access protocols in sensitive applications.

The vulnerability involves insecure handling of ARNs by the system's validation endpoint. Specifically, submitting an "arn:aws-debug:file" ARN grants unauthorized file access. This input-based flaw skips typical security measures, providing improper access to files on the server. Accessible files might range from configuration files to sensitive operational documents. The endpoint enables this exploitation by erroneously validating such ARNs. Overall, the vulnerability underscores the necessity of strict input validation procedures. The below-par authorization checks enable this security lapse.

If exploited, this vulnerability can lead to severe data leaks, including exposure of passwords and private keys. An attacker could read any file the RabbitMQ process has access to, potentially revealing critical system secrets. This can result in unauthorized access to protected systems or data manipulation. Additionally, it poses a risk of subsequent, more severe attacks if these secrets are used to infiltrate other systems. The disclosure of such sensitive information disrupts operational privacy and compromises organizational integrity. Essentially, the exploitation could cripple trust and security within affected systems.

REFERENCES

Solution Advice
  • Upgrade rabbitmq-aws to version 0.2.1 or later.
  • If upgrading is not feasible, disable the aws plugin temporarily.
  • Rotate and secure all secrets stored in readable files promptly.
  • Implement additional file read access controls within your environment.
  • Regularly audit systems for unauthorized access or file read anomalies.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2026-9133 Scanner - Arbitrary File Read vulnerability in rabbitmq-aws | S4E