Cross-Origin Resource Sharing Misconfiguration in RabbitMQ Management Plugin
CVE-2026-66070

7.6HIGH

Key Information:

Vendor

RabbitMQ

Vendor
CVE Published:
23 September 2026

What is CVE-2026-66070?

A significant vulnerability exists in the RabbitMQ management plugin related to improper handling of Cross-Origin Resource Sharing (CORS). When configured with a wildcard CORS origin, the plugin reflects the attacker’s origin in Access-Control-Allow-Origin and erroneously permits credentials. This misconfiguration allows a malicious actor, who may exploit the vulnerability through a crafted web page, to gain unauthorized access to the administrator's session. The affected versions include those prior to 3.13.17, 4.0.22, 4.1.13, and 4.2.6, highlighting the importance of keeping software up-to-date to mitigate risks associated with such vulnerabilities.

Affected Version(s)

rabbitmq-server >= 3.13.0, < 3.13.17 < 3.13.0, 3.13.17

rabbitmq-server >= 4.0.0, < 4.0.22 < 4.0.0, 4.0.22

rabbitmq-server >= 4.1.0, < 4.1.13 < 4.1.0, 4.1.13

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.