Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.6
CVE-2026-66070: RabbitMQ server lets any website use admin credentials
CVE-2026-66070 · published 16 days ago
Summary
If the RabbitMQ management interface is set to allow all origins, it mistakenly returns the requesting website’s address and says credentials are allowed. This lets a malicious site trick a logged‑in administrator into sending authenticated commands to the server. Update RabbitMQ to the latest version or restrict the allowed origins to trusted sites.
What to do
- Update debian rabbitmq-server to version 4.3.0-2.
- Update rabbitmq to version 4.2.6.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | rabbitmq | rabbitmq-server | >= 3.13.0, < 3.13.17 |
| Ubuntu:Pro:16.04:LTS | canonical | rabbitmq-server | All versions |
| Debian:12 | debian | rabbitmq-server | All versions |
| Debian:14 | debian | rabbitmq-server |
< 4.3.0-2 Fix: upgrade to 4.3.0-2
|
| Bitnami | – | rabbitmq |
>= 4.2.0, < 4.2.6 Fix: upgrade to 4.2.6
|
Original advisory text
RabbitMQ: CORS * reflects Origin with Allow-Credentials
RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.17, 4.0.22, 4.1.13, and 4.2.6, match_origin/1 returned the bare reflected Origin and allowed credentials even when the wildcard "" was configured, so the response echoed the attacker's origin together with Access-Control-Allow-Credentials. The affected code is rabbit_mgmt_cors.erl. When the management plugin is configured with a wildcard CORS origin (cors_allow_origins = ""), the handler reflects the request Origin back in Access-Control-Allow-Origin and also sends Access-Control-Allow-Credentials: true. A malicious web page that a signed-in administrator visits can then use that administrator's cached HTTP Basic credentials to issue authenticated, state-changing requests to the management API. Preconditions include The management plugin is configured with the wildcard cors_allow_origins = "*", which is an explicit operator misconfiguration A target administrator has a cached HTTP Basic-auth session in the browser. This issue is fixed in versions 3.13.17, 4.0.22, 4.1.13, and 4.2.6.
References
- https://ubuntu.com/security/CVE-2026-66070 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-66070 Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-66070 Vendor Advisory
- https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6
- https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-p3hp-v9wh-g...
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/66xxx/CVE-2026-66070... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-66070 Vendor Advisory
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-942Permissive Cross-domain Security Policy with Untrusted Domains
Timeline
Published23 Sep 2026
Updated9 Oct 2026
First seen23 Sep 2026
Sources
CVE-2026-66070 · NVD
CVE-2026-66070 · MITRE
UBUNTU-CVE-2026-66070 · OSV
DEBIAN-CVE-2026-66070 · OSV
CVE-2026-66070 · OSV
GHSA-p3hp-v9wh-ghm7 · GHSA
BIT-rabbitmq-2026-66070 · OSV
Track software like this
Free during beta