logo

Critical RabbitMQ Vulnerabilities Enable Broker Takeover via OAuth Secrets

ID: ef2388ef-2c40-5249-8614-95228cd92544

STIX ID: report--ef2388ef-2c40-5249-8614-95228cd92544

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-07-13

Date Updated: 2026-07-18

...
...

Miggo Security disclosed two vulnerabilities in RabbitMQ (CVE-2026-57219 and CVE-2026-57221) affecting versions 3.13.0 and later: CVE-2026-57219 (CVSS 8.7) exposes OAuth client secrets via an obsolete management endpoint and can enable complete broker takeover, while CVE-2026-57221 (CVSS 5.3) allows low-privileged users to enumerate queues and exchanges; patches are available and organizations should apply updates and rotate any exposed OAuth secrets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.