Exploit discussion active in current signal (1 latest mentions)
Immediate actions
Patch broadcom rabbitmq_server systems immediately
Hunt for exploitation attempts and persistence artifacts
Recommended action window: High priority (within 72h)
NVD description
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth 2 client secret on RabbitMQ installations configured with management.oauth_client_secret, exposing credentials to unauthenticated callers when the management plugin and that OAuth configuration are enabled. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.
🚨 CVE-2026-57219 - high 🚨
RabbitMQ Management - OAuth 2 Client Secret Disclosure
> RabbitMQ < 3.13.15, 4.0.20, 4.1.11, and 4.2.6 contains an information disclosure caus...
👾 https://cloud.projectdiscovery.io/library/CVE-2026-57219
@pdnuclei#NucleiTemplates#cve
Post summary
The post announces CVE-2026-57219 as a high‑severity information‑disclosure flaw affecting specific RabbitMQ versions, with no mention of PoC, exploit, or mitigation.
8 new OPEN, 22 new PRO (8 + 14)
LandUpdate808, TA569, ZPHP, TA4903, CVE-2026-57219 (RabiitMQ client-secret disclosure) and more.
https://community.emergingthreats.net/t/ruleset-update-summary-2026-07-14-v11233/3382
Post summary
The text lists new rules added to a security rule set, including a rule covering CVE-2026-57219, but provides no exploits, patches, or evidence of active misuse.
CVE-2026-57219 allows an unauthenticated attacker who can reach the management port (commonly 15672) to retrieve the broker’s confidential OAuth client secret through the obsolete GET /api/auth endpoint. The root cause sits in two functions: is_authorized/2 is hard-coded to always return true for this path, and produce_auth_settings/2 copies the oauth_client_secret value directly into the JSON response. Once the attacker possesses the secret, they can exchange it at the configured identity provider for an administrative token and assume full control over messages, queues, users, virtual hosts, and broker configuration.
The attack sequence is straightforward once the management port is reachable. The attacker issues the unauthenticated GET, receives the secret in the JSON body, and immediately presents that secret to the identity provider in a standard OAuth client-credentials flow. The resulting token carries the broker’s own administrative scope. From that point the attacker can create or delete queues, publish or consume messages at will, enumerate and modify users and permissions, and alter virtual-host configuration without ever authenticating as a legitimate application or user.
The vulnerability affects RabbitMQ versions 3.13.0 and later when the management plugin is enabled and OAuth is configured with a confidential client secret. It does not affect deployments that use no OAuth secret at all or that run without the management plugin. Public clients and PKCE flows that never store a client secret are unaffected because there is nothing to leak.
CVE-2026-57221 lets any authenticated user, even one with zero explicit permissions, enumerate queues and exchanges and read operational statistics. The flaw is missing authorization checks on passive-declare operations inside the management API. The issue does not expose message contents or permit modification, yet it leaks metadata that is valuable in multi-tenant or shared virtual-host environments where operational visibility itself is a boundary concern. An attacker with a low-privilege account can map the topology of every vhost, identify high-value queues by name or message rate, and gather the intelligence needed for targeted follow-on activity without triggering permission errors.
Both issues were introduced when OAuth support expanded in early 2024 and were fixed in the coordinated releases 4.3.0, 4.2.6, 4.1.11, 4.0.20, and 3.13.15. The patch removes the obsolete /api/auth endpoint entirely; OAuth settings now flow only through the authenticated bootstrap.js path. Common identity providers named in the disclosure include Auth0, Microsoft Entra ID, Keycloak, and UAA.
Miggo notes that RabbitMQ sees roughly fifteen million downloads per year and runs in approximately eight percent of containers according to industry census data. At the time of disclosure there was no evidence of in-the-wild exploitation of these specific flaws.
Post summary
The post discloses RabbitMQ OAuth secret leakage and privilege‑escalation flaws, outlines exploitation steps, reports no active attacks, and provides fixed version information.
🐇 RabbitMQ OAuth Secret Exposure Vulnerabilities
A RabbitMQ vulnerability, CVE-2026-57219 (CVSS 8.7), could allow an unauthenticated attacker to retrieve an OAuth client secret with a single GET /api/auth request and potentially obtain administrator privileges.
The accompanying vulnerability, CVE-2026-57221, may allow a low-privilege account to enumerate queue and exchange structures belonging to other tenants.
🔎 Criminal IP findings:
• About 4,100 Internet-exposed RabbitMQ management interfaces
• About 1,800 assets exposed on default port 15672
• Additional assets identified with expired SSL certificates
• Patched versions: 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0 or later
Not every exposed RabbitMQ instance is vulnerable. However, publicly accessible management interfaces may increase reconnaissance and exploitation risk.
👉 Read the full analysis:
https://criminalip.io/knowledge-hub/blog/36570
#RabbitMQ#Cybersecurity#ThreatIntelligence#OAuth#CVE
Post summary
The post details newly disclosed RabbitMQ OAuth secret exposure CVEs with severity information, lists patched versions, and warns that exposed management interfaces increase risk, but provides no active exploitation evidence or PoC.
🐇 RabbitMQ OAuth 시크릿 탈취 취약점 분석
인증 없이 단 한 번의 GET /api/auth 요청만으로 OAuth Client Secret을 탈취하고 관리자 권한까지 획득할 수 있는 RabbitMQ 취약점(CVE-2026-57219, CVSS 8.7)이 공개되었습니다.
함께 공개된 CVE-2026-57221은 최소 권한 계정만으로도 다른 테넌트의 Queue·Exchange 구조를 열람할 수 있는 권한 우회 취약점입니다.
🔍 Criminal IP Asset Search에서 확인한 인터넷 노출 RabbitMQ 관리 인터페이스
• 약 4,100개의 RabbitMQ Management 관리 UI 노출 자산 확인
• 약 1,800개는 기본 HTTP 관리 포트 15672가 외부에 직접 공개
• SSL 인증서가 만료된 RabbitMQ 관리 인터페이스도 다수 확인
영향을 받는 환경이라면 다음 사항을 확인해야 합니다.
✅ RabbitMQ를 3.13.15 / 4.0.20 / 4.1.11 / 4.2.6 / 4.3.0 이상으로 업데이트
✅ OAuth Client Secret 즉시 교체
✅ 관리 인터페이스(15671/15672) 외부 접근 제한
✅ /api/auth 접근 차단(WAF 등 임시 조치)
📄 전체 분석 자세히 보기
https://www.criminalip.io/ko/knowledge-hub/blog/36603
#RabbitMQ #위협인텔리전스 #사이버보안 #공격표면관리
Post summary
The text announces the discovery of a new RabbitMQ OAuth secret‑theft vulnerability (CVE-2026-57219) and a related privilege‑escalation flaw (CVE-2026-57221), detailing the technical aspects and recommending patches and mitigations.
The post analyzes recent OAuth client secret leaks in RabbitMQ that can be exploited with a single unauthenticated request, highlighting the vulnerability but providing no PoC, patch, or evidence of active exploitation.
The post details three high‑severity RabbitMQ CVEs, explains their technical impact, and recommends specific patched releases, emphasizing that the fixes should be applied promptly.
🚨 HIGH - RabbitMQ Management API leaks OAuth client secret via obsolete /api/auth endpoint (CVE-2026-57219)
RabbitMQ’s Management plugin exposes an obsolete GET /api/auth endpoint that can disclose the configured OAuth 2 client secret when management.oauth_client_secret is set. The root cause is improper access control and sensitive information exposure in a legacy API route. An attacker can exploit this remotely by sending an unauthenticated request to the management HTTP API when the management plugin is enabled and OAuth is configured. Impact is credential compromise that can enable unauthorized OAuth client impersonation, token acquisition, and downstream access to protected resources and services.
👉 Affected: rabbitmq-server (all versions before 3.13.15 / 4.0.20 / 4.1.11 / 4.2.6) | Upgrade to 3.13.15, 4.0.20, 4.1.11, or 4.2.6
Post summary
RabbitMQ's obsolete /api/auth endpoint exposes configured OAuth client secrets, allowing remote credential compromise. A patch is available—upgrade to the specified RabbitMQ releases to mitigate the risk.
CVE-2026-57219: RabbitMQ OAuth Client Secret Disclosure - What It Means for Your Business and How to Respond
https://hubs.li/Q04vm5tt0
Post summary
The text announces a RabbitMQ OAuth client secret disclosure vulnerability and outlines its business impact and response guidance, but provides no specific exploits, patches, or evidence of active exploitation.
The text simply provides a link to Microsoft's update guide for CVE-2026-57219 without offering further details on the vulnerability or its exploitation.
RabbitMQ OAuth secret can leak with no login.
CVE-2026-57219: obsolete GET /api/auth returns the client secret if management.oauth_client_secret is set.
Patch: 3.13.15 / 4.0.20 / 4.1.11 / 4.2.6. Rotate if exposed.
https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-pj24-8j6m-vq9q
#CyberSecurity#CVE
Post summary
RabbitMQ CVE-2026-57219 leaks OAuth client secrets via an unauthenticated GET /api/auth; specific patch versions are available and rotation is advised.
@IonutArghire the CVE in the article is wrong
https://www.securityweek.com/rabbitmq-vulnerability-threatens-enterprise-systems/
https://nvd.nist.gov/vuln/detail/CVE-2026-57219
Post summary
The user indicates that the article incorrectly cites CVE-2026-57219 for a RabbitMQ vulnerability, but provides no further details or evidence.