PT-2026-57304 · Vmware+1 · Rabbitmq
CVE-2026-57219
·
Published
2026-07-10
·
Updated
2026-08-26
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
RabbitMQ versions prior to 3.13.15
RabbitMQ versions prior to 4.0.20
RabbitMQ versions prior to 4.1.11
RabbitMQ versions prior to 4.2.6
Description
An obsolete GET '/api/auth' endpoint in the management plugin can disclose the OAuth 2 client secret when the
management.oauth client secret variable is configured. This allows unauthenticated remote callers to obtain sensitive credentials, potentially leading to unauthorized OAuth client impersonation, token acquisition, and access to protected resources and services.Recommendations
Update to version 3.13.15.
Update to version 4.0.20.
Update to version 4.1.11.
Update to version 4.2.6.
Rotate the OAuth client secret if it has been exposed.
Exploit
Fix
Information Disclosure
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rabbitmq