Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-66070

RabbitMQ management API reflects any Origin with credentials when CORS is set to a wildcard

Technology

RabbitMQ

CVSS Score

7.6 / 10.0

Affected Versions

3.13.0 to 3.13.16; 4.0.0 to 4.0.21; 4.1.0 to 4.1.12; 4.2.0 to 4.2.5

Upstream Fix

4.2.6 (public); 3.13.17, 4.0.22, 4.1.13 (commercial)

Published

September 23, 2026

OSSeva Coverage

Fixed upstream

Description

With cors_allow_origins set to "*", the management plugin echoed the request Origin back and sent Access-Control-Allow-Credentials: true. A web page visited by a signed-in administrator could then use the administrator's cached HTTP Basic credentials to make state-changing management API calls. The advisory describes the wildcard setting as an operator misconfiguration.

Upstream record: NVD · CVE.org

Is your RabbitMQ deployment affected?

If you're running 3.13.0 to 3.13.16; 4.0.0 to 4.0.21; 4.1.0 to 4.1.12; 4.2.0 to 4.2.5, you need this patch. Book a discovery call to get covered.