CVE-2026-66070
RabbitMQ management API reflects any Origin with credentials when CORS is set to a wildcard
Technology
RabbitMQ
CVSS Score
7.6 / 10.0
Affected Versions
3.13.0 to 3.13.16; 4.0.0 to 4.0.21; 4.1.0 to 4.1.12; 4.2.0 to 4.2.5
Upstream Fix
4.2.6 (public); 3.13.17, 4.0.22, 4.1.13 (commercial)
Published
September 23, 2026
OSSeva Coverage
Fixed upstream
Description
With cors_allow_origins set to "*", the management plugin echoed the request Origin back and sent Access-Control-Allow-Credentials: true. A web page visited by a signed-in administrator could then use the administrator's cached HTTP Basic credentials to make state-changing management API calls. The advisory describes the wildcard setting as an operator misconfiguration.
Is your RabbitMQ deployment affected?
If you're running 3.13.0 to 3.13.16; 4.0.0 to 4.0.21; 4.1.0 to 4.1.12; 4.2.0 to 4.2.5, you need this patch. Book a discovery call to get covered.