Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-66077

Stored XSS in the RabbitMQ management UI connection page through a TLS client certificate subject

Technology

RabbitMQ

CVSS Score

7.3 / 10.0

Affected Versions

3.13.0 to 3.13.14; 4.0.0 to 4.0.19; 4.1.0 to 4.1.10; 4.2.0 to 4.2.5

Upstream Fix

4.2.6 (public); 3.13.15, 4.0.20, 4.1.11 (commercial)

Published

September 23, 2026

OSSeva Coverage

Fixed upstream

Description

The management UI renders a connection's peer certificate subject and issuer without HTML escaping, and its content security policy allows inline script. With verify_peer enabled, anyone who can get a client certificate from a CA the broker trusts, for example through self-service corporate PKI, can put script in the subject. It runs when an administrator views the connection and can lead to account takeover.

Upstream record: NVD · CVE.org

Is your RabbitMQ deployment affected?

If you're running 3.13.0 to 3.13.14; 4.0.0 to 4.0.19; 4.1.0 to 4.1.10; 4.2.0 to 4.2.5, you need this patch. Book a discovery call to get covered.