PT-2026-97574 · Vmware · Rabbitmq

CVE-2026-66068

·

Published

2026-09-23

·

Updated

2026-09-24

CVSS v4.0

5.6

Medium

VectorAV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions RabbitMQ versions prior to 3.13.15 RabbitMQ versions prior to 4.0.20 RabbitMQ versions prior to 4.1.11 RabbitMQ versions prior to 4.2.6 RabbitMQ versions prior to 4.3.0
Description When the Shovel plugin is enabled with URI-embedded credentials and the log level is set to DEBUG, the system may write the full shovel state map to the broker log file upon the completion of an autodelete shovel. This occurs because the uris field contains plaintext URIs after being processed by rabbit shovel util:deobfuscated uris/2, and there is no format status/1,2 callback in rabbit shovel worker to redact this sensitive information. Consequently, decrypted amqp://user:password@host/ URIs are exposed in the logs, which can be accessed by an attacker with log read permissions.
Recommendations Update RabbitMQ to version 3.13.15 or later. Update RabbitMQ to version 4.0.20 or later. Update RabbitMQ to version 4.1.11 or later. Update RabbitMQ to version 4.2.6 or later. Update RabbitMQ to version 4.3.0 or later. Disable DEBUG logging to prevent the exposure of sensitive credentials in the log files.

Exploit

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-66068
GHSA-9WM4-9M6G-W38X

Affected Products

Rabbitmq