RabbitMQ 3.13.x < 3.13.15 / 4.0.x < 4.0.20 / 4.1.x < 4.1.11 / 4.2.x < 4.2.6 Multiple Vulnerabilities

high Nessus Plugin ID 327581

Synopsis

The RabbitMQ installed on the remote host is affected by multiple vulnerabilities.

Description

The version of RabbitMQ installed on the remote host is affected by multiple vulnerabilities:

- AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication can allow a loopback-restricted user such as guest to connect remotely when traffic is accepted through a trusted PROXY-protocol path and the backend listener is loopback-bound because the loopback check uses the listener-side socket address instead of the real client source.
(CVE-2026-57216)

- The obsolete GET /api/auth endpoint can disclose the OAuth 2 client secret on RabbitMQ installations configured with management.oauth_client_secret, exposing credentials to unauthenticated callers when the management plugin and that OAuth configuration are enabled. (CVE-2026-57219)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to RabbitMQ version 3.13.15, 4.0.20, 4.1.11, 4.2.6, or later.

See Also

http://www.nessus.org/u?253dc836

http://www.nessus.org/u?ec3aa3ed

Plugin Details

Severity: High

ID: 327581

File Name: rabbitmq_3_13_15.nasl

Version: 1.3

Type: Local

Agent: windows, macosx, unix

Family: Misc.

Published: 7/17/2026

Updated: 7/20/2026

Configuration: Enable paranoid mode, Enable thorough checks (optional)

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.8

Percentile: 96.49

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-57216

CVSS v3

Risk Factor: Critical

Base Score: 10

Temporal Score: 9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.7

Threat Score: 7.2

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N

CVSS Score Source: CVE-2026-57219

Vulnerability Information

CPE: cpe:/a:pivotal_software:rabbitmq, cpe:/a:vmware:rabbitmq

Required KB Items: installed_sw/RabbitMQ, Settings/ParanoidReport

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/10/2026

Vulnerability Publication Date: 7/10/2026

Reference Information

CVE: CVE-2026-57216, CVE-2026-57219

IAVA: 2026-A-0683