CVE-2026-57219Patch(broadcom / rabbitmq_server)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch broadcom rabbitmq_server systems immediately
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: High priority (within 72h)

NVD description

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth 2 client secret on RabbitMQ installations configured with management.oauth_client_secret, exposing credentials to unauthenticated callers when the management plugin and that OAuth configuration are enabled. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.

2.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-522

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • rabbitmq_server

Threat summary

  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 12 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 10 signals
  • General: 4 classified signals
  • Disclosure: 4 classified signals
  • Peaked 3d ago at 3 mentions (2026-07-22); latest day: 1
  • 12 total mentions across 8 days

Affected systems

Vendors
Products
rabbitmq_server

Deep dive

Activity timeline12 mentions / 8d
01223Mentions · 2026-07-11: 1Mentions · 2026-07-13: 1Mentions · 2026-07-14: 2Mentions · 2026-07-16: 2Mentions · 2026-07-22: 3Mentions · 2026-07-24: 1Mentions · 2026-08-20: 1Mentions · 2026-08-26: 1Exploit Tool / Code · 2026-07-11: 1Patch / Workaround · 2026-07-11: 1Patch / Workaround · 2026-07-14: 1Patch / Workaround · 2026-07-16: 1Patch / Workaround · 2026-07-22: 2Patch / Workaround · 2026-07-24: 1Technical Details · 2026-07-11: 1Technical Details · 2026-07-14: 2Technical Details · 2026-07-16: 1Technical Details · 2026-07-22: 3Technical Details · 2026-07-24: 1Technical Details · 2026-08-20: 1Technical Details · 2026-08-26: 107-1107-1307-1407-1607-2207-2408-2008-26
Signal classification3 categories
Patch
433.3%
General
433.3%
Disclosure
433.3%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-07-111
Patch1
2026-07-131
General1
2026-07-142
General1Patch1
2026-07-162
General1Patch1
2026-07-223
Disclosure3
2026-07-241
Patch1
2026-08-201
Disclosure1
2026-08-261
General1
Full discourse12 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-57219 - high 🚨 RabbitMQ Management - OAuth 2 Client Secret Disclosure > RabbitMQ < 3.13.15, 4.0.20, 4.1.11, and 4.2.6 contains an information disclosure caus... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-57219 @pdnuclei #NucleiTemplates #cve

    Post summary

    The post announces CVE-2026-57219 as a high‑severity information‑disclosure flaw affecting specific RabbitMQ versions, with no mention of PoC, exploit, or mitigation.

    02056649
    1.3K followersView on X
  • ET Labs@ET_Labs
    General

    8 new OPEN, 22 new PRO (8 + 14) LandUpdate808, TA569, ZPHP, TA4903, CVE-2026-57219 (RabiitMQ client-secret disclosure) and more. https://community.emergingthreats.net/t/ruleset-update-summary-2026-07-14-v11233/3382

    Post summary

    The text lists new rules added to a security rule set, including a rule covering CVE-2026-57219, but provides no exploits, patches, or evidence of active misuse.

    02020304
    5.7K followersView on X
  • stellarbridge@stllrbridge_app
    Patch

    CVE-2026-57219 allows an unauthenticated attacker who can reach the management port (commonly 15672) to retrieve the broker’s confidential OAuth client secret through the obsolete GET /api/auth endpoint. The root cause sits in two functions: is_authorized/2 is hard-coded to always return true for this path, and produce_auth_settings/2 copies the oauth_client_secret value directly into the JSON response. Once the attacker possesses the secret, they can exchange it at the configured identity provider for an administrative token and assume full control over messages, queues, users, virtual hosts, and broker configuration. The attack sequence is straightforward once the management port is reachable. The attacker issues the unauthenticated GET, receives the secret in the JSON body, and immediately presents that secret to the identity provider in a standard OAuth client-credentials flow. The resulting token carries the broker’s own administrative scope. From that point the attacker can create or delete queues, publish or consume messages at will, enumerate and modify users and permissions, and alter virtual-host configuration without ever authenticating as a legitimate application or user. The vulnerability affects RabbitMQ versions 3.13.0 and later when the management plugin is enabled and OAuth is configured with a confidential client secret. It does not affect deployments that use no OAuth secret at all or that run without the management plugin. Public clients and PKCE flows that never store a client secret are unaffected because there is nothing to leak. CVE-2026-57221 lets any authenticated user, even one with zero explicit permissions, enumerate queues and exchanges and read operational statistics. The flaw is missing authorization checks on passive-declare operations inside the management API. The issue does not expose message contents or permit modification, yet it leaks metadata that is valuable in multi-tenant or shared virtual-host environments where operational visibility itself is a boundary concern. An attacker with a low-privilege account can map the topology of every vhost, identify high-value queues by name or message rate, and gather the intelligence needed for targeted follow-on activity without triggering permission errors. Both issues were introduced when OAuth support expanded in early 2024 and were fixed in the coordinated releases 4.3.0, 4.2.6, 4.1.11, 4.0.20, and 3.13.15. The patch removes the obsolete /api/auth endpoint entirely; OAuth settings now flow only through the authenticated bootstrap.js path. Common identity providers named in the disclosure include Auth0, Microsoft Entra ID, Keycloak, and UAA. Miggo notes that RabbitMQ sees roughly fifteen million downloads per year and runs in approximately eight percent of containers according to industry census data. At the time of disclosure there was no evidence of in-the-wild exploitation of these specific flaws.

    Post summary

    The post discloses RabbitMQ OAuth secret leakage and privilege‑escalation flaws, outlines exploitation steps, reports no active attacks, and provides fixed version information.

    0001171
    10 followersView on X
  • Criminal IP@CriminalIP_US
    Disclosure

    🐇 RabbitMQ OAuth Secret Exposure Vulnerabilities A RabbitMQ vulnerability, CVE-2026-57219 (CVSS 8.7), could allow an unauthenticated attacker to retrieve an OAuth client secret with a single GET /api/auth request and potentially obtain administrator privileges. The accompanying vulnerability, CVE-2026-57221, may allow a low-privilege account to enumerate queue and exchange structures belonging to other tenants. 🔎 Criminal IP findings: • About 4,100 Internet-exposed RabbitMQ management interfaces • About 1,800 assets exposed on default port 15672 • Additional assets identified with expired SSL certificates • Patched versions: 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0 or later Not every exposed RabbitMQ instance is vulnerable. However, publicly accessible management interfaces may increase reconnaissance and exploitation risk. 👉 Read the full analysis: https://criminalip.io/knowledge-hub/blog/36570 #RabbitMQ #Cybersecurity #ThreatIntelligence #OAuth #CVE

    Post summary

    The post details newly disclosed RabbitMQ OAuth secret exposure CVEs with severity information, lists patched versions, and warns that exposed management interfaces increase risk, but provides no active exploitation evidence or PoC.

    02000311
    4.9K followersView on X
  • Criminal IP Korea@CriminalIP_KR
    Disclosure

    🐇 RabbitMQ OAuth 시크릿 탈취 취약점 분석​ 인증 없이 단 한 번의 GET /api/auth 요청만으로 OAuth Client Secret을 탈취하고 관리자 권한까지 획득할 수 있는 RabbitMQ 취약점(CVE-2026-57219, CVSS 8.7)이 공개되었습니다.​ 함께 공개된 CVE-2026-57221은 최소 권한 계정만으로도 다른 테넌트의 Queue·Exchange 구조를 열람할 수 있는 권한 우회 취약점입니다.​ 🔍 Criminal IP Asset Search에서 확인한 인터넷 노출 RabbitMQ 관리 인터페이스​ • 약 4,100개의 RabbitMQ Management 관리 UI 노출 자산 확인​ • 약 1,800개는 기본 HTTP 관리 포트 15672가 외부에 직접 공개​ • SSL 인증서가 만료된 RabbitMQ 관리 인터페이스도 다수 확인​ 영향을 받는 환경이라면 다음 사항을 확인해야 합니다.​ ✅ RabbitMQ를 3.13.15 / 4.0.20 / 4.1.11 / 4.2.6 / 4.3.0 이상으로 업데이트​ ✅ OAuth Client Secret 즉시 교체​ ✅ 관리 인터페이스(15671/15672) 외부 접근 제한​ ✅ /api/auth 접근 차단(WAF 등 임시 조치)​ 📄 전체 분석 자세히 보기​ https://www.criminalip.io/ko/knowledge-hub/blog/36603 ​ #RabbitMQ #위협인텔리전스 #사이버보안 #공격표면관리

    Post summary

    The text announces the discovery of a new RabbitMQ OAuth secret‑theft vulnerability (CVE-2026-57219) and a related privilege‑escalation flaw (CVE-2026-57221), detailing the technical aspects and recommending patches and mitigations.

    00020170
    670 followersView on X
  • Criminal IP Japan@CriminalIP_JP
    Disclosure

    🐇 RabbitMQ OAuthシークレット漏えいの脆弱性を分析​ RabbitMQで公開された2件のアクセス制御の脆弱性、CVE-2026-57219・CVE-2026-57221について分析しました。​ CVE-2026-57219は、認証なしのHTTPリクエスト1回でOAuthクライアントシークレットが漏えいし、管理者アクセストークンの取得につながる可能性があります。​ 🔎 Criminal IPで確認された主な結果​ • title: RabbitMQ Management → 約4,100件​ • title: RabbitMQ Management port:15672 → 約1,800件​ • SSL証明書が期限切れのRabbitMQ管理UIも確認​ これらの結果は、すべてのRabbitMQ管理インターフェースが脆弱であることを意味するものではありません。しかし、管理UIが外部公開されている場合、攻撃者による偵察や認証情報漏えいのリスクが高まる可能性があります。​ 📌 詳細はこちら​ https://www.criminalip.io/ja/knowledge-hub/blog/9566​ #RabbitMQ #CVE #脆弱性 #サイバーセキュリティ #サイバー攻撃

    Post summary

    The post analyzes recent OAuth client secret leaks in RabbitMQ that can be exploited with a single unauthenticated request, highlighting the vulnerability but providing no PoC, patch, or evidence of active exploitation.

    00020192
    1.4K followersView on X
  • connect24h@connect24h
    Patch

    これも使っている人、要注意案件。RabbitMQの認証境界は総点検が必要。 CVE-2026-57219/57217/57216の3件、最大CVSS 8.7。OAuth 2構成ではGET /api/authからclient secretが無認証露出し、Khepri障害時はtopic権限がfail-openしてcross-tenant routingが通る。trusted PROXY protocol+loopback listenerでは、資格情報を持つ遠隔者がguest sessionを確立できる。 CSIRT初動は、management pluginとmanagement.oauth_client_secret、PROXY protocol、loopback_users、Khepri timeout前後の権限外routing、guestのremote接続を棚卸し。露出可能性があればsecretもrotateする。修正版は3.13.15/4.1.11/4.2.6、4.0系は57217のみ4.0.21、他2件は4.0.20。平常時の試験では見落とす。保守待ちにしないでほしい。#セキュリティ

    Post summary

    The post details three high‑severity RabbitMQ CVEs, explains their technical impact, and recommends specific patched releases, emphasizing that the fixes should be applied promptly.

    10000353
    4.5K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 HIGH - RabbitMQ Management API leaks OAuth client secret via obsolete /api/auth endpoint (CVE-2026-57219) RabbitMQ’s Management plugin exposes an obsolete GET /api/auth endpoint that can disclose the configured OAuth 2 client secret when management.oauth_client_secret is set. The root cause is improper access control and sensitive information exposure in a legacy API route. An attacker can exploit this remotely by sending an unauthenticated request to the management HTTP API when the management plugin is enabled and OAuth is configured. Impact is credential compromise that can enable unauthorized OAuth client impersonation, token acquisition, and downstream access to protected resources and services. 👉 Affected: rabbitmq-server (all versions before 3.13.15 / 4.0.20 / 4.1.11 / 4.2.6) | Upgrade to 3.13.15, 4.0.20, 4.1.11, or 4.2.6

    Post summary

    RabbitMQ's obsolete /api/auth endpoint exposes configured OAuth client secrets, allowing remote credential compromise. A patch is available—upgrade to the specified RabbitMQ releases to mitigate the risk.

    00010138
    247 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-57219: RabbitMQ OAuth Client Secret Disclosure - What It Means for Your Business and How to Respond https://hubs.li/Q04vm5tt0

    Post summary

    The text announces a RabbitMQ OAuth client secret disclosure vulnerability and outlines its business impact and response guidance, but provides no specific exploits, patches, or evidence of active exploitation.

    0000023
    33 followersView on X
  • connect24h@connect24h
    General

    ソース: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57219

    Post summary

    The text simply provides a link to Microsoft's update guide for CVE-2026-57219 without offering further details on the vulnerability or its exploitation.

    00000110
    4.5K followersView on X
  • SecEngCyGy@snypet86
    Patch

    RabbitMQ OAuth secret can leak with no login. CVE-2026-57219: obsolete GET /api/auth returns the client secret if management.oauth_client_secret is set. Patch: 3.13.15 / 4.0.20 / 4.1.11 / 4.2.6. Rotate if exposed. https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-pj24-8j6m-vq9q #CyberSecurity #CVE

    Post summary

    RabbitMQ CVE-2026-57219 leaks OAuth client secrets via an unauthenticated GET /api/auth; specific patch versions are available and rotation is advised.

    0000051
    21 followersView on X
  • Aureliopuente@aureliopuente
    General

    @IonutArghire the CVE in the article is wrong https://www.securityweek.com/rabbitmq-vulnerability-threatens-enterprise-systems/ https://nvd.nist.gov/vuln/detail/CVE-2026-57219

    Post summary

    The user indicates that the article incorrectly cites CVE-2026-57219 for a RabbitMQ vulnerability, but provides no further details or evidence.

    0000054
    428 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbroadcomrabbitmq_server---

Explore more