/Vulnerability Library

RabbitMQ Management - OAuth 2 Client Secret Disclosure

CVE-2026-57219
Verified

Description

RabbitMQ < 3.13.15, 4.0.20, 4.1.11, and 4.2.6 contains an information disclosure caused by the obsolete GET /api/auth endpoint exposing OAuth 2 client secrets when management.oauth_client_secret is configured, letting unauthenticated attackers access sensitive credentials, exploit requires management plugin and OAuth configuration enabled.

Severity

High

CVSS Score

7.5

Exploit Probability

3%

Affected Product

rabbitmq_server

Published Date

August 19, 2026

Template Author

aryu-ru

CVE-2026-57219.yaml
7.5Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2026-57219
CWE ID:
cwe-522

References

https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-pj24-8j6m-vq9qhttps://github.com/rabbitmq/rabbitmq-server/commit/98b1daf740237c85941e8addcbea6e74f4a2743chttps://nvd.nist.gov/vuln/detail/CVE-2026-57219

Remediation Steps

Update to versions 3.13.15, 4.0.20, 4.1.11, or 4.2.6 or later.