PT-2026-97568 · Vmware · Rabbitmq

CVE-2026-67404

·

Published

2026-09-23

·

Updated

2026-09-29

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions RabbitMQ versions prior to 3.13.15 RabbitMQ versions prior to 4.0.20 RabbitMQ versions prior to 4.1.11 RabbitMQ versions prior to 4.2.6 RabbitMQ versions prior to 4.3.0
Description When no CA bundle is available, the ssl options/1 function falls back to [{verify, verify none}] without issuing a warning. This allows a man-in-the-middle attacker to forge the JWKS (JSON Web Key Set) response, causing the broker to accept arbitrary JWTs (JSON Web Tokens). This occurs when the OAuth2 plugin is active without a configured cacertfile and the OS CA bundle is empty or unreadable, such as in minimal container environments.
Recommendations Update to version 3.13.15. Update to version 4.0.20. Update to version 4.1.11. Update to version 4.2.6. Update to version 4.3.0.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67404
GHSA-37WX-R6Q9-6FHJ

Affected Products

Rabbitmq