PT-2026-97587 · Vmware · Rabbitmq

CVE-2026-67405

·

Published

2026-09-23

·

Updated

2026-09-24

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions RabbitMQ versions prior to 3.13.15 RabbitMQ versions prior to 4.0.20 RabbitMQ versions prior to 4.1.11 RabbitMQ versions prior to 4.2.6 RabbitMQ versions prior to 4.3.0
Description The Web-MQTT handler and the Web-STOMP handler do not validate the Origin header during the WebSocket upgrade process. When the ssl cert login configuration is enabled, browsers automatically present the client certificate, allowing malicious JavaScript executing in a victim's browser to authenticate as that user. This issue requires specific non-default configurations to be active: use http auth for Web-STOMP or ssl cert login for both plugins. The issue does not affect the default in-band CONNECT credential configuration.
Recommendations Update to version 3.13.15 Update to version 4.0.20 Update to version 4.1.11 Update to version 4.2.6 Update to version 4.3.0 Disable the ssl cert login configuration to prevent automatic client certificate presentation. Disable the use http auth configuration for Web-STOMP.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67405
GHSA-9C4F-RXXM-88Q3

Affected Products

Rabbitmq