PT-2026-98911 · Vmware · Rabbitmq
CVE-2026-67237
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v4.0
7.5
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
RabbitMQ versions 4.2.0 through 4.2.7
RabbitMQ versions 4.3.0 through 4.3.1
Description
The
set token auth/2 function inserts a bearer token from the Authorization header or access token cookie into OAuth bootstrap JavaScript without proper escaping. This allows an attacker to execute arbitrary JavaScript within the management UI origin. The issue is accessible before authentication if management.oauth enabled is set to true. Exploitation via the cookie path requires the attacker to plant an access token cookie on the management host.Recommendations
Update RabbitMQ versions 4.2.0 through 4.2.7 to version 4.2.8.
Update RabbitMQ versions 4.3.0 through 4.3.1 to version 4.3.2.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rabbitmq