Two disclosed RabbitMQ authorization flaws put a spotlight on the broker’s per-vhost isolation model and the risks that arise when identity tokens are mapped too loosely to permissions.