Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in RabbitMQ Server - CVE-2026-67421
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information and perform unauthorized administrative actions.
The vulnerability exists due to improper output neutralization for html in RabbitMQ Management OAuth error handling when rendering an AMQP authorization-error reason in the OAuth management UI. A remote user can create a queue with a crafted html name and induce a management administrator to click Get Message(s) to disclose sensitive information and perform unauthorized administrative actions.
The issue is exploitable only when the OAuth management UI is enabled, the victim can see the queue but lacks AMQP read permission for it, automatic UI refresh remains active, and user interaction is required.