OAuth2 Client Secret Exposure in RabbitMQ Management UI by RabbitMQ
CVE-2026-67410

8.2HIGH

Key Information:

Vendor

RabbitMQ

Vendor
CVE Published:
25 September 2026

What is CVE-2026-67410?

An exposed OAuth2 client secret has been identified in the RabbitMQ Management UI, where the configured client secret is retrievable via an unauthenticated JavaScript endpoint. This vulnerability allows unauthorized users who can access the management UI to extract the OAuth2 client secret without authentication. This flaw can lead to token theft and client impersonation, potentially allowing an attacker to hijack user sessions or gain unauthorized access to broker functionalities. Versions 4.3.3 and 4.2.9 have been released to address this issue. It's critical for users to upgrade to these versions to protect against such vulnerabilities.

Affected Version(s)

rabbitmq-server >= 4.3.0, < 4.3.3 < 4.3.0, 4.3.3

rabbitmq-server >= 4.2.0, < 4.2.9 < 4.2.0, 4.2.9

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.