Bug 2539724 (CVE-2026-66070) - CVE-2026-66070 rabbitmq-server: RabbitMQ: Cross-Origin Resource Sharing (CORS) misconfiguration allows unauthorized actions
Summary: CVE-2026-66070 rabbitmq-server: RabbitMQ: Cross-Origin Resource Sharing (CORS...
Keywords:
Status: NEW
Alias: CVE-2026-66070
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2540085
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-23 20:12 UTC by OSIDB Bzimport
Modified: 2026-09-24 14:05 UTC (History)
7 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-23 20:12:52 UTC
RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.17, 4.0.22, 4.1.13, and 4.2.6, match_origin/1 returned the bare reflected Origin and allowed credentials even when the wildcard "" was configured, so the response echoed the attacker's origin together with Access-Control-Allow-Credentials. The affected code is rabbit_mgmt_cors.erl. When the management plugin is configured with a wildcard CORS origin (cors_allow_origins = ""), the handler reflects the request Origin back in Access-Control-Allow-Origin and also sends Access-Control-Allow-Credentials: true. A malicious web page that a signed-in administrator visits can then use that administrator's cached HTTP Basic credentials to issue authenticated, state-changing requests to the management API. Preconditions include The management plugin is configured with the wildcard cors_allow_origins = "*", which is an explicit operator misconfiguration A target administrator has a cached HTTP Basic-auth session in the browser. This issue is fixed in versions 3.13.17, 4.0.22, 4.1.13, and 4.2.6.


Note You need to log in before you can comment on or make changes to this bug.