Executive brief
RabbitMQ is a widely used message broker that facilitates communication between different software applications. A security flaw in its management interface could allow unauthorized individuals to view sensitive OAuth 2 client secrets. If exploited, this could lead to unauthorized access to the messaging system, potentially compromising data integrity or allowing attackers to intercept private communications.
Technical details
An information disclosure vulnerability exists in the RabbitMQ Management Plugin due to the presence of a deprecated and obsolete API endpoint. The 'GET /api/auth' endpoint, which has been superseded by 'bootstrap.js' since version 3.11, fails to properly protect sensitive configuration data. When RabbitMQ is configured with 'management.oauth_client_secret', an unauthenticated remote attacker can query this endpoint to retrieve the OAuth 2 client secret. This secret can then be used to impersonate the RabbitMQ management client or gain unauthorized access to the broker. The vulnerability is resolved by the complete removal of the deprecated endpoint in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.
Affected products
- RabbitMQ RabbitMQ Server >= 3.13.0, < 3.13.15; >= 4.0.0, < 4.0.20; >= 4.1.0, < 4.1.11; >= 4.2.0, < 4.2.6
Timeline
- 2026-04-14: patched: Fixes merged into main and backport branches
- 2026-04-23: advisory: Release of version 4.2.6 containing the fix
- 2026-07-10: disclosed: CVE-2026-57219 published
References
- https://github.com/rabbitmq/rabbitmq-server/commit/98b1daf740237c85941e8addcbea6e74f4a2743c
- https://github.com/rabbitmq/rabbitmq-server/commit/aa387c4451e7b674df3e3ba89df86a99d697cc7f
- https://github.com/rabbitmq/rabbitmq-server/pull/16083
- https://github.com/rabbitmq/rabbitmq-server/pull/16086
- https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6
- https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-pj24-8j6m-vq9q