CVE-2026-57219 Details
Description
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth 2 client secret on RabbitMQ installations configured with management.oauth_client_secret, exposing credentials to unauthenticated callers when the management plugin and that OAuth configuration are enabled. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.
A vulnerability exists in RabbitMQ versions prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, allowing the unauthorized disclosure of OAuth 2 client secrets. This issue arises from a deprecated GET /api/auth endpoint, which can expose sensitive credentials to unauthenticated users when the management plugin is active and certain OAuth configurations are in place. The vulnerability is present in RabbitMQ installations that use OAuth 2 with the management.oauth_client_secret setting, and where the management plugin is enabled.
Users can upgrade to RabbitMQ versions 3.13.15, 4.0.20, 4.1.11, or 4.2.6 to address this vulnerability. Alternatively, the 'rabbitmq_auth_backend_oauth2' plugin can be disabled and a different authentication backend used. If monitoring is needed, consider using Prometheus and Grafana instead of the RabbitMQ management plugin.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-522 | Insufficiently Protected Credentials | [email protected] |
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| broadcom rabbitmq server | >= 3.13.0, < 4.2.6 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 29, 2026 | CVE Modified | CISA-ADP |
| Jul 16, 2026 | CVE Modified | CISA-ADP |
| Jul 14, 2026 | CVE Modified | CISA-ADP |
| Jul 13, 2026 | Initial Analysis | [email protected] |
| Jul 10, 2026 | New CVE Received | [email protected] |