CVE-2026-57219: RabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurations

Overview

Severity
High (CVSS 7.5)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploit Status
Not Exploited
Patch Tuesday
2026-Jul
Released
2026-07-15
Last Updated
2026-07-22
EPSS Score
1.99% (percentile: 79.0%)

Detection & Weaponization (1 sources)

Maturity: Exploit

  • Nuclei templates: RabbitMQ Management - OAuth 2 Client Secret Disclosure

Affected Products (1)

Other

  • 21487-17084

Revision History

  • 2026-07-15: Information published.
  • 2026-07-22: Information published.