⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

RabbitMQ Flaws Expose OAuth Secrets and Cross-Tenant Queue Metadata

July 14, 2026

Cybersecurity researchers at Miggo have disclosed two access control vulnerabilities in the RabbitMQ message broker that could allow attackers to leak OAuth client secrets and bypass tenant boundaries. The flaws, present since early 2024, affect RabbitMQ versions 3.13.0 and later and have been patched in versions 4.3.0, 4.2.6, 4.1.11, 4.0.20, and 3.13.15. No active exploitation has been reported.

The first vulnerability, CVE-2026-57219 (CVSS 8.7), involves an obsolete HTTP API endpoint (GET /api/auth) that leaks the OAuth client secret in installations using the management.oauth_client_secret configuration key. An attacker can exchange this secret for an administrator token, gaining full control over messages, queues, users, and broker settings. The second flaw, CVE-2026-57221 (CVSS 5.3), allows any authenticated user to enumerate queue and exchange names, and read message and consumer counts across tenants without proper authorization.

Mitigation steps include patching to the latest versions, rotating OAuth client secrets if the management interface is internet-facing, restricting access to port 15672, separating tenants by virtual host, and implementing firewall rules to block the vulnerable endpoint on unpatched instances. The disclosure follows earlier critical RabbitMQ fixes for TLS client-authentication bypass (CVSS 9.1) and JWKS response forgery (CVSS 9.2).

CVEs: CVE-2026-57219, CVE-2026-57221

Companies: Miggo, RabbitMQ

Products: RabbitMQ