Cross-Origin Resource Sharing Misconfiguration in RabbitMQ Management Plugin
CVE-2026-66070
What is CVE-2026-66070?
A significant vulnerability exists in the RabbitMQ management plugin related to improper handling of Cross-Origin Resource Sharing (CORS). When configured with a wildcard CORS origin, the plugin reflects the attacker’s origin in Access-Control-Allow-Origin and erroneously permits credentials. This misconfiguration allows a malicious actor, who may exploit the vulnerability through a crafted web page, to gain unauthorized access to the administrator's session. The affected versions include those prior to 3.13.17, 4.0.22, 4.1.13, and 4.2.6, highlighting the importance of keeping software up-to-date to mitigate risks associated with such vulnerabilities.
Affected Version(s)
rabbitmq-server >= 3.13.0, < 3.13.17 < 3.13.0, 3.13.17
rabbitmq-server >= 4.0.0, < 4.0.22 < 4.0.0, 4.0.22
rabbitmq-server >= 4.1.0, < 4.1.13 < 4.1.0, 4.1.13
