PT-2026-57304 · Vmware+1 · Rabbitmq

CVE-2026-57219

·

Published

2026-07-10

·

Updated

2026-08-26

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions RabbitMQ versions prior to 3.13.15 RabbitMQ versions prior to 4.0.20 RabbitMQ versions prior to 4.1.11 RabbitMQ versions prior to 4.2.6
Description An obsolete GET '/api/auth' endpoint in the management plugin can disclose the OAuth 2 client secret when the management.oauth client secret variable is configured. This allows unauthenticated remote callers to obtain sensitive credentials, potentially leading to unauthorized OAuth client impersonation, token acquisition, and access to protected resources and services.
Recommendations Update to version 3.13.15. Update to version 4.0.20. Update to version 4.1.11. Update to version 4.2.6. Rotate the OAuth client secret if it has been exposed.

Exploit

Fix

Information Disclosure

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92334
CVE-2026-57219
GHSA-PJ24-8J6M-VQ9Q
RHSA-2026:35939
RHSA-2026:35940

Affected Products

Rabbitmq