CVE-2026-67231: CWE-295: Improper Certificate Validation in rabbitmq rabbitmq-server
CVE-2026-67231 is a critical vulnerability in rabbitmq-server affecting versions prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6. The issue arises from improper certificate validation in the trust-store plugin, which overrides certain bad certificate errors when a presented certificate matches a whitelisted certificate based only on issuer name and serial number. This allows an attacker who knows or can guess the issuer DN and serial number of a whitelisted certificate to bypass TLS client authentication by presenting a forged self-signed certificate. The vulnerability requires the rabbitmq_trust_store plugin to be enabled and used as the TLS verify function. Fixed versions have been released to address this issue.
AI Analysis
Technical Summary
RabbitMQ's trust-store plugin improperly validates TLS client certificates by overriding errors for certificates that match a whitelist based solely on the issuer's distinguished name and serial number, without verifying the public key or signature. The whitelist check uses a simple ETS member lookup and does not perform full certificate path validation, as the trust anchors list is empty. This flaw enables an attacker who knows or can guess the issuer DN and serial number of a whitelisted certificate to connect using a forged self-signed certificate, effectively bypassing TLS client authentication. The vulnerability affects rabbitmq-server versions >=3.13.0 <3.13.15, >=4.0.0 <4.0.20, >=4.1.0 <4.1.11, and >=4.2.0 <4.2.6. It is fixed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0.
Potential Impact
An attacker who can guess or know the issuer distinguished name and serial number of a whitelisted certificate can bypass TLS client authentication on affected RabbitMQ servers with the trust-store plugin enabled. This allows unauthorized access to the messaging broker, potentially leading to unauthorized message publishing or consumption. The vulnerability does not require privileges or user interaction and has a high impact on confidentiality and integrity of communications.
Mitigation Recommendations
A fixed version of rabbitmq-server is available: upgrade to 3.13.15, 4.0.20, 4.1.11, 4.2.6, or later. The vendor has released official fixes addressing this improper certificate validation issue. If upgrading immediately is not possible, consider disabling the rabbitmq_trust_store plugin or avoiding its use as the TLS verify function until patched. Patch status is confirmed by the vendor advisory.
CVE-2026-67231: CWE-295: Improper Certificate Validation in rabbitmq rabbitmq-server
Description
CVE-2026-67231 is a critical vulnerability in rabbitmq-server affecting versions prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6. The issue arises from improper certificate validation in the trust-store plugin, which overrides certain bad certificate errors when a presented certificate matches a whitelisted certificate based only on issuer name and serial number. This allows an attacker who knows or can guess the issuer DN and serial number of a whitelisted certificate to bypass TLS client authentication by presenting a forged self-signed certificate. The vulnerability requires the rabbitmq_trust_store plugin to be enabled and used as the TLS verify function. Fixed versions have been released to address this issue.
CVSS v4.0
Score 9.1critical
Affected software
rabbitmq
rabbitmq-server
pkg:github/rabbitmq/rabbitmq-serverRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
RabbitMQ's trust-store plugin improperly validates TLS client certificates by overriding errors for certificates that match a whitelist based solely on the issuer's distinguished name and serial number, without verifying the public key or signature. The whitelist check uses a simple ETS member lookup and does not perform full certificate path validation, as the trust anchors list is empty. This flaw enables an attacker who knows or can guess the issuer DN and serial number of a whitelisted certificate to connect using a forged self-signed certificate, effectively bypassing TLS client authentication. The vulnerability affects rabbitmq-server versions >=3.13.0 <3.13.15, >=4.0.0 <4.0.20, >=4.1.0 <4.1.11, and >=4.2.0 <4.2.6. It is fixed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0.
Potential Impact
An attacker who can guess or know the issuer distinguished name and serial number of a whitelisted certificate can bypass TLS client authentication on affected RabbitMQ servers with the trust-store plugin enabled. This allows unauthorized access to the messaging broker, potentially leading to unauthorized message publishing or consumption. The vulnerability does not require privileges or user interaction and has a high impact on confidentiality and integrity of communications.
Mitigation Recommendations
A fixed version of rabbitmq-server is available: upgrade to 3.13.15, 4.0.20, 4.1.11, 4.2.6, or later. The vendor has released official fixes addressing this improper certificate validation issue. If upgrading immediately is not possible, consider disabling the rabbitmq_trust_store plugin or avoiding its use as the TLS verify function until patched. Patch status is confirmed by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-07-28T19:50:39.438Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab48379f7a7c54106b23ca0
Added to database: 09/24/2026, 01:57:13 UTC
Last enriched: 09/24/2026, 01:58:42 UTC
Last updated: 09/24/2026, 04:41:54 UTC
Views: 22
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.