PT-2026-97561 · Vmware · Rabbitmq

CVE-2026-66077

·

Published

2026-09-23

·

Updated

2026-09-29

CVSS v4.0

7.3

High

VectorAV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions RabbitMQ versions prior to 3.13.15 RabbitMQ versions prior to 4.0.20 RabbitMQ versions prior to 4.1.11 RabbitMQ versions prior to 4.2.6
Description The management UI fails to HTML-escape data rendered via EJS 1.0. Specifically, the connection.ejs and streamConnection.ejs files render connection.ssl details.peer cert subject and peer cert issuer directly into the page. These values are provided by the rabbit ssl:peer cert subject/1 function, which formats the Distinguished Name (DN) as a string without escaping. An attacker possessing a TLS client certificate signed by a CA trusted by the broker can embed JavaScript within the certificate's Subject DN. If the TLS listener is configured with ssl options.verify = verify peer and an administrator views the connection detail page, the embedded script executes in the administrator's browser session. This can lead to full account takeover, including the ability to create users and export definitions, as the Content Security Policy (CSP) allows 'unsafe-inline' scripts.
Recommendations Update RabbitMQ to version 3.13.15 or later. Update RabbitMQ to version 4.0.20 or later. Update RabbitMQ to version 4.1.11 or later. Update RabbitMQ to version 4.2.6 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-66077
GHSA-RJCF-35R5-XW38

Affected Products

Rabbitmq