SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-57214

MEDIUM · CVSS 5.4 EPSS 0.22% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

The RabbitMQ management UI prior to version 4.2.5 is vulnerable due to improper escaping of the x-internal-purpose queue or exchange argument in HTML title attributes, which can lead to cross-site scripting (XSS) attacks. This vulnerability allows an authenticated user to execute JavaScript in another user's browser, potentially compromising sensitive information. Organizations using affected versions of RabbitMQ should prioritize updating to version 4.2.5 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-57214
Severity
MEDIUM
CVSS
5.4
EPSS
0.22%
Exchange Java

Original NVD Description

RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the x-internal-purpose queue or exchange argument into an HTML title attribute without proper escaping on the Queues and Exchanges pages, allowing a user with permission to declare a queue or exchange to execute JavaScript in another user's browser. This issue is fixed in version 4.2.5.

Related CVEs

Other vulnerabilities affecting the same vendor(s)