CVE-2026-25112
Privilege Escalation in Genetec RabbitMQ Deployment
Publication date: 2026-05-26
Last updated on: 2026-05-26
Assigner: Genetec Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| genetec | rabbitmq | to 3.13.7.19 (exc) |
| genetec | rabbitmq | From 3.13.7.3 (inc) |
| genetec | mission_control | * |
| genetec | industrial_iot | From 5.x (inc) |
| genetec | airport_operational_manager | * |
| genetec | restricted_security_area_surveillance | * |
| genetec | inter_system_gateway | * |
| genetec | sipelia | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-732 | The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
CVE-2026-25112 is a high-severity privilege escalation vulnerability affecting the deployment of RabbitMQ in certain Genetec products. It occurs because RabbitMQ, running with elevated privileges, inadvertently relies on an untrusted diagnostic utility due to a misplaced component. This flaw allows an attacker with local access to the machine to gain higher privileges than intended.
How can this vulnerability impact me? :
If exploited, this vulnerability could allow an attacker who already has local access to your system to escalate their privileges, potentially gaining administrative or higher-level permissions. This could lead to unauthorized control over affected Genetec products and systems, increasing the risk of data compromise, system manipulation, or disruption of services.
What immediate steps should I take to mitigate this vulnerability?
To mitigate the privilege escalation vulnerability in Genetec RabbitMQ deployments, you should update RabbitMQ to version 3.13.7.19 if you are deploying new systems.
For existing deployments, apply the mitigation utility SecurityUtility_CVE-2026-25112_RabbitMQ.exe available through the Genetec Technical Assistance Portal (GTAP).
As a temporary workaround, restrict access to the folder ProgramData\Genetec\RabbitMQ so that only administrator users have access.