PT-2026-97561 · Vmware · Rabbitmq
CVE-2026-66077
·
Published
2026-09-23
·
Updated
2026-09-29
CVSS v4.0
7.3
High
| Vector | AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
RabbitMQ versions prior to 3.13.15
RabbitMQ versions prior to 4.0.20
RabbitMQ versions prior to 4.1.11
RabbitMQ versions prior to 4.2.6
Description
The management UI fails to HTML-escape data rendered via EJS 1.0. Specifically, the
connection.ejs and streamConnection.ejs files render connection.ssl details.peer cert subject and peer cert issuer directly into the page. These values are provided by the rabbit ssl:peer cert subject/1 function, which formats the Distinguished Name (DN) as a string without escaping. An attacker possessing a TLS client certificate signed by a CA trusted by the broker can embed JavaScript within the certificate's Subject DN. If the TLS listener is configured with ssl options.verify = verify peer and an administrator views the connection detail page, the embedded script executes in the administrator's browser session. This can lead to full account takeover, including the ability to create users and export definitions, as the Content Security Policy (CSP) allows 'unsafe-inline' scripts.Recommendations
Update RabbitMQ to version 3.13.15 or later.
Update RabbitMQ to version 4.0.20 or later.
Update RabbitMQ to version 4.1.11 or later.
Update RabbitMQ to version 4.2.6 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rabbitmq