OAuth 2 Client Secret Exposure in RabbitMQ Management Plugin
CVE-2026-57219

8.7HIGH

Key Information:

Vendor

RabbitMQ

Vendor
CVE Published:
10 July 2026

What is CVE-2026-57219?

CVE-2026-57219 is a vulnerability identified in the RabbitMQ management plugin prior to specific versions (3.13.15, 4.0.20, 4.1.11, and 4.2.6). RabbitMQ is an open-source message broker widely used for managing messages and streams across various applications. This particular vulnerability arises from the obsolete GET /api/auth endpoint, which can inadvertently expose OAuth 2 client secrets when certain configurations are in place. If the management plugin is enabled alongside the OAuth configuration, this flaw can allow unauthenticated users to access sensitive credentials, which can severely compromise the security of the RabbitMQ installation. The potential for unauthorized access to these secrets creates a serious risk for organizations relying on RabbitMQ, as attackers could utilize this information to authenticate and gain control over messaging services.

Potential impact of CVE-2026-57219

  1. Unauthorized Access to Messaging Services: With the exposure of OAuth 2 client secrets, attackers may gain access to messaging and streaming operations within RabbitMQ. This could enable them to manipulate or intercept messages, leading to unauthorized actions and data breaches.

  2. Credential Compromise and Abuse: The leakage of sensitive OAuth credentials can allow malicious actors to forge access tokens or impersonate users, leading to further criminal actions within organizational infrastructures, including data theft or service disruptions.

  3. Regulatory and Compliance Risks: Organizations utilizing RabbitMQ could face compliance issues and potential penalties due to the unauthorized exposure of credentials, particularly if sensitive or regulated data is involved. This can lead to significant reputational damage and financial repercussions, undermining trust with customers and partners.

Affected Version(s)

rabbitmq-server >= 4.2.0, < 4.2.6 < 4.2.0, 4.2.6

rabbitmq-server >= 4.1.0, < 4.1.11 < 4.1.0, 4.1.11

rabbitmq-server >= 4.0.0, < 4.0.21 < 4.0.0, 4.0.21

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.