PT-2026-98911 · Vmware · Rabbitmq

CVE-2026-67237

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v4.0

7.5

High

VectorAV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions RabbitMQ versions 4.2.0 through 4.2.7 RabbitMQ versions 4.3.0 through 4.3.1
Description The set token auth/2 function inserts a bearer token from the Authorization header or access token cookie into OAuth bootstrap JavaScript without proper escaping. This allows an attacker to execute arbitrary JavaScript within the management UI origin. The issue is accessible before authentication if management.oauth enabled is set to true. Exploitation via the cookie path requires the attacker to plant an access token cookie on the management host.
Recommendations Update RabbitMQ versions 4.2.0 through 4.2.7 to version 4.2.8. Update RabbitMQ versions 4.3.0 through 4.3.1 to version 4.3.2.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67237
GHSA-2RF7-F6R6-8RWH

Affected Products

Rabbitmq