OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-67231

CRITICAL · CVSS 9.1 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The RabbitMQ trust-store plugin is vulnerable to a TLS client-authentication bypass, allowing attackers to connect using forged self-signed certificates if they know the issuer distinguished name (DN) and serial number of a whitelisted certificate. This critical vulnerability can lead to unauthorized access to messaging and streaming services, making it essential for organizations using affected versions to prioritize upgrading to the fixed releases (3.13.15, 4.0.20, 4.1.11, 4.2.6, or 4.3.0) to mitigate the risk. Users of RabbitMQ who have enabled the trust-store plugin should take immediate action to secure their systems.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-67231
Severity
CRITICAL
CVSS
9.1
EPSS
0.25%

Original NVD Description

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The trust-store plugin installs a verify_fun that overrides {bad_cert, unknown_ca} / {bad_cert, selfsigned_peer} when the presented cert "matches" a whitelisted one. The match key is extract_issuer_id/1 → public_key:pkix_issuer_id/2 → {IssuerName, SerialNumber} , both fields are taken verbatim from the presented certificate body and contain no public-key, SKI, fingerprint or signature material. is_whitelisted/1 is a pure ets:member lookup; the stored full DER is used only for list/0 display and is never compared against the presented cert. cacerts is [], so the whitelisted cert is never used as a trust anchor for path validation either. TLS client-authentication bypass: an attacker who knows the issuer DN + serial of any whitelisted certificate can connect with a forged self-signed cert. Preconditions include rabbitmq_trust_store plugin enabled and used as the TLS verify_fun Attacker knows or can guess the {Issuer, Serial} of at least one whitelisted cert (non-secret; exposed via CLI/logs/any cert copy). This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0.