S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Aug 30, 2026

CVE-2026-57219 Scanner

CVE-2026-57219 Scanner - Information Disclosure vulnerability in RabbitMQ Management

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.9k
Times Used
continuous scan runs
6.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-57219
8.7
CVSShigh
Exploitable remotely over the internet · no authentication required.

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth 2 client secret on RabbitMQ installations configured with management.oauth_client_secret, exposing credentials to unauthenticated callers when the management plugin and that OAuth configuration are enabled. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.

Attack Vector
Network
Privileges Req.
None
User Interaction
A
Affected
rabbitmq-serverby rabbitmq
>= 4.2.0, < 4.2.6
Updated Sep 11, 2026View on NVD →
Detail

RabbitMQ Management is widely used for managing RabbitMQ, an open-source message broker software. It is utilized in various environments, including enterprises and developers for reliable messaging and communication handling. The management plugin provides users with a robust API and interface for monitoring and controlling RabbitMQ queues, exchanges, and more. Companies rely on RabbitMQ for message queuing, inter-service communication, and event distribution. The software integrates with many systems, supporting numerous messaging protocols and scaling effectively. Its flexibility and scalability make it an essential component for distributed systems requiring robust messaging solutions.

The detected vulnerability relates to an information disclosure issue affecting RabbitMQ Management. Specifically, it concerns the obsolete GET /api/auth endpoint that exposes OAuth 2 client secrets. This vulnerability can be exploited if the management.oauth_client_secret is configured, potentially allowing unauthorized users to access sensitive credentials. Addressing this issue is crucial for organizations using the affected RabbitMQ versions to prevent unauthorized access. Information disclosure vulnerabilities are particularly severe when they expose authentication credentials, leading to further security breaches. Maintaining updated software to mitigate such vulnerabilities is imperative for system security.

On a technical level, this vulnerability is due to the GET /api/auth endpoint in RabbitMQ Management, which reveals OAuth 2 client secrets. The presence of the `management.oauth_client_secret` configuration under vulnerable versions allows the endpoint to expose client secrets. Attackers can exploit this endpoint without authentication, as the vulnerability is accessible through unauthenticated requests. The issue persists in versions below 3.13.15, 4.0.20, 4.1.11, and 4.2.6. Patching the affected versions is essential to protect against unauthorized access to confidential client secret information. Understanding this endpoint and verifying it against patched versions is crucial for mitigating the risk.

If exploited by malicious actors, this vulnerability can lead to unauthorized access to OAuth 2 client secrets. Such exposure potentially enables attackers to perform actions under the guise of authorized users, leading to significant security breaches. The risk of unauthorized access also translates to potential data theft, manipulation, and system disruption. Companies may face reputational damage, breach of trust, and regulatory penalties. Therefore, organizations must address such vulnerabilities promptly to avoid adverse impacts on their operations and comply with security standards.

REFERENCES

Solution Advice
  • Update RabbitMQ to version 3.13.15, 4.0.20, 4.1.11, 4.2.6 or later to address the issue.
  • Regularly monitor and apply security patches and updates to RabbitMQ Management.
  • Review OAuth configurations to ensure they do not expose sensitive information.
  • Implement network security measures to prevent unauthorized access to management endpoints.
  • Conduct security audits to identify and mitigate similar vulnerabilities proactively.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2026-57219 Scanner - Information Disclosure vulnerability in RabbitMQ Management | S4E