Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in RabbitMQ Server - CVE-2026-67421

 

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in RabbitMQ Server - CVE-2026-67421

Published: August 18, 2026


Vulnerability identifier: #VU143940
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-67421
CWE-ID: CWE-80
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information and perform unauthorized administrative actions.

The vulnerability exists due to improper output neutralization for html in RabbitMQ Management OAuth error handling when rendering an AMQP authorization-error reason in the OAuth management UI. A remote user can create a queue with a crafted html name and induce a management administrator to click Get Message(s) to disclose sensitive information and perform unauthorized administrative actions.

The issue is exploitable only when the OAuth management UI is enabled, the victim can see the queue but lacks AMQP read permission for it, automatic UI refresh remains active, and user interaction is required.


Affected software

RabbitMQ Server

How to mitigate CVE-2026-67421

Install security update from vendor's website.

RabbitMQ Server - addressed in versions 3.13.19, 4.0.24, 4.1.15, 4.2.10, 4.3.5

External References

Related Security Bulletins