OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-67410

HIGH · CVSS 7.1 EPSS 0.40% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

RabbitMQ versions 4.2.0 to 4.3.3 and 4.2.9 are vulnerable due to an unauthenticated JavaScript endpoint that exposes the OAuth2 client secret, allowing any user with access to the management UI port to retrieve sensitive credentials. This vulnerability can lead to token theft and client impersonation, posing a significant risk to the integrity of the messaging system. Organizations using affected RabbitMQ versions with OAuth2 authentication enabled should prioritize patching to versions 4.3.3 or 4.2.9 to mitigate this high-severity threat.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-67410
Severity
HIGH
CVSS
7.1
EPSS
0.40%
Java

Original NVD Description

RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.3.3 and 4.2.9, OAuth2 Client Secret Exposed via Unauthenticated JavaScript Endpoint (CWE-200). when OAuth2 authentication is enabled for the RabbitMQ Management UI and the configured flow, IDP use a client secret, the oauthclientsecret configuration value is included in the JavaScript served by the unauthenticated endpoint /js/oidc-oauth/bootstrap.js. Any user who can reach the management UI port can retrieve the OAuth2 client secret without Files: deps/rabbitmqmanagement/src/rabbitmgmtwmauth.erl, line 186 deps/rabbitmqmanagement/src/rabbitmgmtoauthbootstrap.erl, lines 35-50 deps/rabbitmqmanagement/src/rabbitmgmtdispatcher.erl, lines 45-49 (route registration) Code Path: 1. The route /js/oidc-oauth/bootstrap.js is registered as a plain Cowboy handler (rabbitmgmtdispatcher.erl:46): Credential exposure for the affected configuration: OAuth2 client secret is accessible without any authentication Token theft: Attacker can complete the authorization code flow using stolen authorization codes Client impersonation: Attacker can make requests. Any RabbitMQ deployment with: This issue is fixed in versions 4.3.3 and 4.2.9.

Related CVEs

Other vulnerabilities affecting the same vendor(s)