Skip to main content

CVE-2026-67231: CWE-295: Improper Certificate Validation in rabbitmq rabbitmq-server

0
Critical
VulnerabilityCVE-2026-67231cvecve-2026-67231cwe-295
Published: 09/23/2026 (09/23/2026, 20:47:36 UTC)
Source: CVE Database V5
Vendor/Project: rabbitmq
Product: rabbitmq-server

Description

CVE-2026-67231 is a critical vulnerability in rabbitmq-server affecting versions prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6. The issue arises from improper certificate validation in the trust-store plugin, which overrides certain bad certificate errors when a presented certificate matches a whitelisted certificate based only on issuer name and serial number. This allows an attacker who knows or can guess the issuer DN and serial number of a whitelisted certificate to bypass TLS client authentication by presenting a forged self-signed certificate. The vulnerability requires the rabbitmq_trust_store plugin to be enabled and used as the TLS verify function. Fixed versions have been released to address this issue.

CVSS v4.0

Score 9.1critical

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
High
Vuln. Integrity
High
Vuln. Availability
None
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Affected software

rabbitmq

rabbitmq-server

Affected versions
>=3.13.0 <3.13.15>=4.0.0 <4.0.20>=4.1.0 <4.1.11>=4.2.0 <4.2.6
GitHub Actionsmore threats →ai
rabbitmq/rabbitmq-server
pkg:github/rabbitmq/rabbitmq-server
Affected versions
>=3.13.0 <3.13.15>=4.0.0 <4.0.20>=4.1.0 <4.1.11>=4.2.0 <4.2.6

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/24/2026, 01:58:42 UTC

Technical Analysis

RabbitMQ's trust-store plugin improperly validates TLS client certificates by overriding errors for certificates that match a whitelist based solely on the issuer's distinguished name and serial number, without verifying the public key or signature. The whitelist check uses a simple ETS member lookup and does not perform full certificate path validation, as the trust anchors list is empty. This flaw enables an attacker who knows or can guess the issuer DN and serial number of a whitelisted certificate to connect using a forged self-signed certificate, effectively bypassing TLS client authentication. The vulnerability affects rabbitmq-server versions >=3.13.0 <3.13.15, >=4.0.0 <4.0.20, >=4.1.0 <4.1.11, and >=4.2.0 <4.2.6. It is fixed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0.

Potential Impact

An attacker who can guess or know the issuer distinguished name and serial number of a whitelisted certificate can bypass TLS client authentication on affected RabbitMQ servers with the trust-store plugin enabled. This allows unauthorized access to the messaging broker, potentially leading to unauthorized message publishing or consumption. The vulnerability does not require privileges or user interaction and has a high impact on confidentiality and integrity of communications.

Mitigation Recommendations

A fixed version of rabbitmq-server is available: upgrade to 3.13.15, 4.0.20, 4.1.11, 4.2.6, or later. The vendor has released official fixes addressing this improper certificate validation issue. If upgrading immediately is not possible, consider disabling the rabbitmq_trust_store plugin or avoiding its use as the TLS verify function until patched. Patch status is confirmed by the vendor advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-07-28T19:50:39.438Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6ab48379f7a7c54106b23ca0

Added to database: 09/24/2026, 01:57:13 UTC

Last enriched: 09/24/2026, 01:58:42 UTC

Last updated: 09/24/2026, 04:41:54 UTC

Views: 22

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses