OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-67237

HIGH · CVSS 7.5 EPSS 0.48% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

RabbitMQ versions 4.2.0 to 4.2.8 and 4.3.2 are vulnerable due to improper handling of bearer tokens in OAuth bootstrap JavaScript, which can lead to cross-site scripting (XSS) attacks in the management UI. This vulnerability allows attackers to execute arbitrary JavaScript if they can control the token content, particularly when management.oauth_enabled is enabled and an access_token cookie is planted. Organizations using affected versions should prioritize updating to versions 4.2.8 or 4.3.2 to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-67237
Severity
HIGH
CVSS
7.5
EPSS
0.48%
Java

Original NVD Description

RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.8 and 4.3.2, set_token_auth/2 inserted a bearer token from the Authorization header or access_token cookie into OAuth bootstrap JavaScript without escaping, allowing attacker-controlled token content to execute JavaScript in the management UI origin. The endpoint is exposed before authentication only when management.oauth_enabled is true, and exploitation through the cookie path additionally requires the attacker to plant an access_token cookie on the management host. This issue is fixed in versions 4.2.8 and 4.3.2.