Skip to main content

CVE-2026-66077: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in rabbitmq rabbitmq-server

0
High
VulnerabilityCVE-2026-66077cvecve-2026-66077cwe-79
Published: 09/23/2026 (09/23/2026, 20:03:42 UTC)
Source: CVE Database V5
Vendor/Project: rabbitmq
Product: rabbitmq-server

Description

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6, The management UI uses EJS 1.0 in which <%= ... %> does NOT HTML-escape. connection.ejs:135 renders <%= connection.ssl_details.peer_cert_subject %> (and peer_cert_issuer) directly into the page. The same pattern appears in streamConnection.ejs:102,106,110. The values come from rabbit_ssl:peer_cert_subject/1 which formats the DN as a string without HTML escaping. The verifier corrected the original researcher's claim: this is reachable only when the listener is configured with verify_peer (so the certificate must be signed by a CA in the broker's trust store, not arbitrary self-signed); however, in deployments using mTLS for client authentication, any user who can request a certificate from the organisational CA controls the Subject CN. An attacker who can obtain a TLS client certificate signed by a CA the broker trusts (with verify_peer enabled) can embed JavaScript in the certificate's Subject DN. When any administrator views that connection in the management UI, the script executes in the admin's browser session, allowing full account takeover (create users, export definitions, etc.). The management UI's CSP includes 'unsafe-inline', so inline script execution is not blocked. Preconditions include TLS listener configured with ssl_options.verify = verify_peer Attacker can obtain a CA-signed client certificate with attacker-chosen Subject (e.g. self-service corporate PKI, or rabbitmq_trust_store plugin in use) Administrator views the connection detail page. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.

CVSS v4.0

Score 7.3high

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
Low
User Interaction
Active
Vuln. Confidentiality
High
Vuln. Integrity
High
Vuln. Availability
Low
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N

Affected software

rabbitmq

rabbitmq-server

Affected versions
>=3.13.0 <3.13.15>=4.0.0 <4.0.20>=4.1.0 <4.1.11>=4.2.0 <4.2.6
GitHub Actionsmore threats →ai
rabbitmq/rabbitmq-server
pkg:github/rabbitmq/rabbitmq-server
Affected versions
=3.13.0=3.13.15=4.0.0=4.0.20=4.1.0=4.1.11=4.2.0=4.2.6

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/23/2026, 20:47:51 UTC

Technical Analysis

RabbitMQ's management UI prior to versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6 uses EJS 1.0 templates that render certain certificate subject fields (peer_cert_subject and peer_cert_issuer) without HTML escaping. These fields are sourced from the TLS client certificate's Subject DN, formatted as a string without escaping. When the TLS listener is configured with ssl_options.verify = verify_peer, the broker requires client certificates signed by a trusted CA. An attacker who can obtain such a certificate with a malicious JavaScript payload embedded in the Subject DN can cause script execution in the administrator's browser when viewing the connection details page in the management UI. The management UI's Content Security Policy includes 'unsafe-inline', allowing inline script execution. This leads to potential full account takeover, including creating users and exporting definitions. The vulnerability is addressed in RabbitMQ versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.

Potential Impact

An attacker who can obtain a TLS client certificate signed by a CA trusted by the RabbitMQ broker (with verify_peer enabled) can inject malicious JavaScript into the certificate's Subject DN. When an administrator views the affected connection in the management UI, the script executes in the administrator's browser context, enabling full account takeover capabilities such as creating users and exporting definitions. This compromises the confidentiality and integrity of the RabbitMQ management interface and potentially the entire messaging infrastructure managed by RabbitMQ.

Mitigation Recommendations

This vulnerability is fixed in RabbitMQ versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6. Upgrading to one of these versions is the recommended remediation. If upgrading is not immediately possible, restrict access to the management UI and ensure that only trusted administrators can view connection details. Additionally, review the TLS client certificate issuance policies to prevent untrusted or attacker-controlled certificates from being accepted. However, the primary and official fix is to upgrade to the patched versions.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-07-23T23:25:28.898Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6ab43797f7a7c541064a9653

Added to database: 09/23/2026, 20:33:27 UTC

Last enriched: 09/23/2026, 20:47:51 UTC

Last updated: 09/24/2026, 01:57:04 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses