CVE-2026-66070

Description

A flaw was found in RabbitMQ. When the management plugin is configured with a wildcard Cross-Origin Resource Sharing (CORS) origin, it incorrectly reflects the attacker's origin and allows credentials. This vulnerability enables a malicious web page to leverage a signed-in administrator's cached credentials. Consequently, an attacker can issue authenticated requests to the management API, potentially leading to unauthorized actions.

Statement

Red Hat rates this flaw IMPORTANT in products that ship affected RabbitMQ builds. If the Management plugin allows wildcard CORS and an administrator has cached HTTP Basic credentials, a malicious website visited by that administrator can make authenticated Management API requests, potentially exposing sensitive information or changing broker configuration.

Mitigation

Replace wildcard CORS with explicit trusted origins and avoid administrator Basic credentials in browsers used for untrusted sites.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score8.1N/AN/A
Attack VectorNetworkN/AN/A
Attack ComplexityLowN/AN/A
Privileges RequiredNoneN/AN/A
User InteractionRequiredN/AN/A
ScopeUnchangedN/AN/A
ConfidentialityHighN/AN/A
Integrity ImpactHighN/AN/A
Availability ImpactNoneN/AN/A

Vector

Red Hat: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Understanding the Weakness (CWE)

Confidentiality,Integrity,Availability,Access Control

Technical Impact: Execute Unauthorized Code or Commands; Bypass Protection Mechanism; Read Application Data; Varies by Context

With an overly permissive policy file, an attacker may be able to bypass the web browser's same-origin policy and conduct many of the same attacks seen in Cross-Site Scripting (CWE-79). An attacker can exploit the weakness to transfer private information from the victim's machine to the attacker, manipulate or steal cookies that may include session information, create malicious requests to a web site on behalf of the victim, or execute malicious code on the end user systems. Other damaging attacks include the disclosure of end user files, installation of Trojan horse programs, redirecting the user to some other page or site, running ActiveX controls (under Microsoft Internet Explorer) from sites that a user perceives as trustworthy, and modifying presentation of content.

Frequently Asked Questions

Want to get errata notifications? Sign up here.