AMQP Authorization Error in RabbitMQ Management UI
CVE-2026-67421

4.5MEDIUM

Key Information:

Vendor

RabbitMQ

Vendor
CVE Published:
25 September 2026

What is CVE-2026-67421?

In RabbitMQ versions from 3.13.0 to 3.13.19, as well as several versions of 4.0, 4.1, 4.2, and 4.3, a vulnerability exists within the RabbitMQ Management UI that can expose sensitive information. If the OAuth management interface is enabled, an attacker can potentially manipulate the management UI to render an authorization error that includes a queue name controlled by the attacker. This can occur when a management administrator views messages from a queue for which they lack read permissions. The compromised Content Security Policy may allow the attacker to target a victim's Authorization header when the administrator interacts with a specially crafted message, particularly through a relative refresh that neglects to define base-uri and connect-src directives. This vulnerability is addressed in the fixed versions 3.13.19, 4.0.24, 4.1.15, 4.2.10, and 4.3.5.

Affected Version(s)

rabbitmq-server >= 3.13.0, < 3.13.19 < 3.13.0, 3.13.19

rabbitmq-server >= 4.0.0, < 4.0.24 < 4.0.0, 4.0.24

rabbitmq-server >= 4.1.0, < 4.1.15 < 4.1.0, 4.1.15

References

CVSS V4

Score:
4.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.