Critical RabbitMQ Vulnerabilities Enable Broker Takeover via OAuth Secrets
ID: ef2388ef-2c40-5249-8614-95228cd92544
STIX ID: report--ef2388ef-2c40-5249-8614-95228cd92544
Feed Name: ThreatCluster
Threat Score
Miggo Security disclosed two vulnerabilities in RabbitMQ (CVE-2026-57219 and CVE-2026-57221) affecting versions 3.13.0 and later: CVE-2026-57219 (CVSS 8.7) exposes OAuth client secrets via an obsolete management endpoint and can enable complete broker takeover, while CVE-2026-57221 (CVSS 5.3) allows low-privileged users to enumerate queues and exchanges; patches are available and organizations should apply updates and rotate any exposed OAuth secrets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
