OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-67421

MEDIUM · CVSS 6.8 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

RabbitMQ Management versions prior to specified updates are vulnerable to an authorization error that can expose sensitive information, specifically the victim's Authorization header, to an attacker-controlled endpoint. This exploitation requires specific permissions and actions from a management administrator, making it a targeted risk for organizations using RabbitMQ with OAuth management enabled. Users of affected versions should prioritize upgrading to the fixed releases to mitigate potential data exposure risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-67421
Severity
MEDIUM
CVSS
6.8
EPSS
0.30%

Original NVD Description

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.19, 4.0.24, 4.1.15, 4.2.10, and 4.3.5, RabbitMQ Management rendered an AMQP authorization-error reason containing an attacker-controlled queue name as HTML when the OAuth management UI was enabled. Exploitation requires an attacker with queue configure permission, a management administrator who can see but cannot read that queue, and the administrator clicking Get Message(s). A queue name containing a base element can then retarget the automatic relative refresh because the Content Security Policy omits base-uri and connect-src, and an attacker endpoint that permits the management origin through CORS can receive the victim's Authorization header. This issue is fixed in versions 3.13.19, 4.0.24, 4.1.15, 4.2.10, and 4.3.5.

Related CVEs

Other vulnerabilities affecting the same vendor(s)