CVE-2026-67405
Last modified
CVE-2026-67405 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, Neither the Web-MQTT handler (deps/rabbitmq_web_mqtt/src/rabbit_web_mqtt_handler.erl:104) nor the Web-STOMP handler (deps/rabbitmq_web_stomp/src/rabbit_web_stomp_handler.erl:102) validates the Origin header on the WebSocket upgrade. EPSS estimates a 0.13% chance of exploitation in the next 30 days.
Description
RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, Neither the Web-MQTT handler (deps/rabbitmq_web_mqtt/src/rabbit_web_mqtt_handler.erl:104) nor the Web-STOMP handler (deps/rabbitmq_web_stomp/src/rabbit_web_stomp_handler.erl:102) validates the Origin header on the WebSocket upgrade. Under ssl_cert_login=true, the browser presents the client certificate automatically, so an attacker's JavaScript running in the victim's browser can authenticate as the victim. Preconditions include The non-default configuration use_http_auth=true (Web-STOMP) or ssl_cert_login=true (both plugins) must be enabled. The issue is harmless under the default in-band CONNECT credential configuration.. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| rabbitmq | rabbitmq-server | >= 3.13.0, < 3.13.15; >= 4.0.0, < 4.0.20; >= 4.1.0, < 4.1.11; >= 4.2.0, < 4.2.6 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-67405?
How severe is CVE-2026-67405?
How do I fix CVE-2026-67405?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-67399Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.…9.3
- CVE-2026-6740The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Webs…6.4
- CVE-2026-67401A vulnerability in cPanel allows a mail-enabled account to a…9.9
- CVE-2026-67402An insecure Apache configuration in ConfigServer Security & …9.2
- CVE-2026-67403Cash Collect contains an improper authorization vulnerabilit…9
- CVE-2026-67404RabbitMQ is a messaging and streaming broker. Prior to versi…9.2
- CVE-2026-67406RabbitMQ is a messaging and streaming broker. From 4.0.0 unt…4.6
- CVE-2026-67407RabbitMQ is a messaging and streaming broker. From 4.0.0 unt…5.1
- CVE-2026-67408RabbitMQ is a messaging and streaming broker. From 4.1.0 unt…7.1
- CVE-2026-67409RabbitMQ is a messaging and streaming broker. From 3.13.0 un…8.2
- CVE-2026-6741The LatePoint – Calendar Booking Plugin for Appointments and…8.8
- CVE-2026-67410RabbitMQ is a messaging and streaming broker. From 4.2.0 unt…8.2
Are you affected by CVE-2026-67405?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
