Known CVE
RabbitMQ Management - OAuth 2 Client Secret Disclosure
RabbitMQ < 3.13.15, 4.0.20, 4.1.11, and 4.2.6 contains an information disclosure caused by the obsolete GET /api/auth endpoint exposing OAuth 2 client secrets when management.oauth_client_secret is configured, letting unauthenticated attackers access sensitive credentials, exploit requires management plugin and OAuth configuration enabled.
CVE-2026-57219
High2026CVSS 7.5CWE-522
cve2026 · rabbitmq · broadcom · oauth · exposure · unauth
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website