PT-2026-97574 · Vmware · Rabbitmq
CVE-2026-66068
·
Published
2026-09-23
·
Updated
2026-09-24
CVSS v4.0
5.6
Medium
| Vector | AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
RabbitMQ versions prior to 3.13.15
RabbitMQ versions prior to 4.0.20
RabbitMQ versions prior to 4.1.11
RabbitMQ versions prior to 4.2.6
RabbitMQ versions prior to 4.3.0
Description
When the Shovel plugin is enabled with URI-embedded credentials and the log level is set to DEBUG, the system may write the full shovel state map to the broker log file upon the completion of an autodelete shovel. This occurs because the
uris field contains plaintext URIs after being processed by rabbit shovel util:deobfuscated uris/2, and there is no format status/1,2 callback in rabbit shovel worker to redact this sensitive information. Consequently, decrypted amqp://user:password@host/ URIs are exposed in the logs, which can be accessed by an attacker with log read permissions.Recommendations
Update RabbitMQ to version 3.13.15 or later.
Update RabbitMQ to version 4.0.20 or later.
Update RabbitMQ to version 4.1.11 or later.
Update RabbitMQ to version 4.2.6 or later.
Update RabbitMQ to version 4.3.0 or later.
Disable DEBUG logging to prevent the exposure of sensitive credentials in the log files.
Exploit
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rabbitmq