CVE-2026-9133 Details
Description
Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws before version 0.2.1. A debug ARN scheme (arn:aws-debug:file) accepted by the PUT /api/aws/arn/validate validation endpoint might allow remote authenticated users to perform arbitrary file reads on any file accessible to the RabbitMQ process. To remediate this issue, customers should upgrade to version 0.2.1 of rabbitmq-aws. If RabbitMQ is configured to use TLS for connections, we also recommend rotating any associated private certificate keys.
A vulnerability exists in the Amazon MQ RabbitMQ-AWS plugin, specifically in versions 0.1.0 through 0.2.0, due to active debug code in the ARN resolver. This debug code introduces a scheme (arn:aws-debug:file) that can be used with the validation endpoint PUT /api/aws/arn/validate. Remote authenticated users may exploit this to read any file accessible to the RabbitMQ process, potentially including sensitive information such as TLS certificates, private keys, and passwords.
Users are advised to upgrade to RabbitMQ-AWS version 0.2.1, which removes the debug ARN format. If the plugin has been used to read sensitive files, such as TLS private keys, those secrets should be rotated. The plugin can also be temporarily disabled, but this will remove ARN resolution at startup, requiring a fallback to filesystem-based certificate configuration.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 20, 2026CISA-ADP
Assessed May 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://aws.amazon.com/security/security-bulletins/2026-034-aws/ | AMZN | AdvisoryBundleRemedy |
| https://github.com/amazon-mq/rabbitmq-aws/releases/tag/0.2.1 | AMZN | Release NotesVendor |
| https://github.com/amazon-mq/rabbitmq-aws/security/advisories/GHSA-8554-wg4r-7hxm | AMZN | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-489 | Active Debug Code | AMZN |
Affected Products
| Product | Versions |
|---|---|
| Amazon rabbitmq-aws | >= 0.1.0, <= 0.2.0 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | AMZN |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 20, 2026 | New CVE Received | AMZN |
Volerion