Junglewise Threat Intelligence

CVE-2026-57219: RabbitMQ information disclosure in management API auth endpoint

CVE-2026-57219 · Severity: info · CVSS 8.7 · Published 2026-07-10

Technologies: Broadcom Rabbitmq Server. Vendors: Broadcom, RabbitMQ.

Executive brief

RabbitMQ is a widely used message broker that facilitates communication between different software applications. A security flaw in its management interface could allow unauthorized individuals to view sensitive OAuth 2 client secrets. If exploited, this could lead to unauthorized access to the messaging system, potentially compromising data integrity or allowing attackers to intercept private communications.

Technical details

An information disclosure vulnerability exists in the RabbitMQ Management Plugin due to the presence of a deprecated and obsolete API endpoint. The 'GET /api/auth' endpoint, which has been superseded by 'bootstrap.js' since version 3.11, fails to properly protect sensitive configuration data. When RabbitMQ is configured with 'management.oauth_client_secret', an unauthenticated remote attacker can query this endpoint to retrieve the OAuth 2 client secret. This secret can then be used to impersonate the RabbitMQ management client or gain unauthorized access to the broker. The vulnerability is resolved by the complete removal of the deprecated endpoint in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.

Affected products

  • RabbitMQ RabbitMQ Server >= 3.13.0, < 3.13.15; >= 4.0.0, < 4.0.20; >= 4.1.0, < 4.1.11; >= 4.2.0, < 4.2.6

Timeline

  • 2026-04-14: patched: Fixes merged into main and backport branches
  • 2026-04-23: advisory: Release of version 4.2.6 containing the fix
  • 2026-07-10: disclosed: CVE-2026-57219 published

References

Related threats