OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-67236

HIGH · CVSS 8.2 EPSS 0.12% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

RabbitMQ versions 4.2.0 to 4.2.8 and 4.3.2 are vulnerable due to a flaw in the authentication cookie management, which exposes base64-encoded username and password credentials without adequate security protections. This vulnerability allows attackers to potentially retrieve sensitive login information through cross-site scripting, network interception, or local access to the browser's cookie store. Organizations using affected versions of RabbitMQ should prioritize upgrading to versions 4.2.8 or 4.3.2 to mitigate the risk of credential theft.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-67236
Severity
HIGH
CVSS
8.2
EPSS
0.12%

Original NVD Description

RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.8 and 4.3.2, a successful POST /login caused is_authorized/2 to set an auth cookie containing base64-encoded username:password credentials without HttpOnly, Secure, SameSite, or expiration protections. Because base64 is encoding rather than encryption, an attacker with same-origin cross-site scripting, an HTTP-readable network position, or local access to the browser cookie store could recover the actual login credentials; older browsers that treated an absent SameSite attribute as None also sent the cookie cross-site. This issue is fixed in versions 4.2.8 and 4.3.2.