PT-2026-97558 · Vmware · Rabbitmq

CVE-2026-66070

·

Published

2026-09-23

·

Updated

2026-09-23

CVSS v4.0

7.6

High

VectorAV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions RabbitMQ versions prior to 3.13.17 RabbitMQ versions prior to 4.0.22 RabbitMQ versions prior to 4.1.13 RabbitMQ versions prior to 4.2.6
Description In the management plugin, the match origin/1 function within rabbit mgmt cors.erl incorrectly reflects the request Origin in the Access-Control-Allow-Origin header and sends Access-Control-Allow-Credentials: true when the cors allow origins variable is configured with a wildcard. This behavior allows a malicious web page visited by a signed-in administrator to use cached HTTP Basic credentials to perform authenticated, state-changing requests to the management API. This occurs when the management plugin is misconfigured with cors allow origins = "*" and the administrator has an active session in the browser.
Recommendations Update to version 3.13.17 or later. Update to version 4.0.22 or later. Update to version 4.1.13 or later. Update to version 4.2.6 or later. Avoid configuring the management plugin with the wildcard cors allow origins = "*".

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-66070
GHSA-P3HP-V9WH-GHM7

Affected Products

Rabbitmq