OAuth2 Client Secret Exposure in RabbitMQ Management UI by RabbitMQ
CVE-2026-67410
8.2HIGH
What is CVE-2026-67410?
An exposed OAuth2 client secret has been identified in the RabbitMQ Management UI, where the configured client secret is retrievable via an unauthenticated JavaScript endpoint. This vulnerability allows unauthorized users who can access the management UI to extract the OAuth2 client secret without authentication. This flaw can lead to token theft and client impersonation, potentially allowing an attacker to hijack user sessions or gain unauthorized access to broker functionalities. Versions 4.3.3 and 4.2.9 have been released to address this issue. It's critical for users to upgrade to these versions to protect against such vulnerabilities.
Affected Version(s)
rabbitmq-server >= 4.3.0, < 4.3.3 < 4.3.0, 4.3.3
rabbitmq-server >= 4.2.0, < 4.2.9 < 4.2.0, 4.2.9
