PatchSiren cyber security CVE debrief
CVE-2026-67239 rabbitmq CVE debrief
CVE-2026-67239 is a high-severity vulnerability in RabbitMQ, a messaging and streaming broker. An attacker can exploit this vulnerability to conduct Stored Cross-Site Scripting (XSS) attacks via TLS peer-certificate DN in the stream-management UI. This requires a non-default configuration: a stream TLS listener with 'verifypeer' and an attacker-obtainable trusted certificate with a malicious Distinguished Name (DN).
- Vendor
- rabbitmq
- Product
- rabbitmq-server
- CVSS
- HIGH 7.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-25
- Original CVE updated
- 2026-09-25
- Advisory published
- 2026-09-25
- Advisory updated
- 2026-09-25
Who should care
RabbitMQ administrators and users who have the stream-management UI enabled with a TLS listener using 'verifypeer' should assess their exposure and prioritize verification and remediation.
Why it matters
CVE-2026-67239 is a high-severity vulnerability in RabbitMQ that allows Stored XSS attacks via TLS peer-certificate DN in the stream-management UI. Defenders should prioritize verifying and updating RabbitMQ versions, reviewing access to the stream-management UI, and ensuring only trusted certificates are used.
- An attacker can conduct Stored XSS attacks via TLS peer-certificate DN in the stream-management UI
- Defenders need to verify and update RabbitMQ versions to prevent exploitation
- Remediation requires updating RabbitMQ to a fixed version and reviewing access to the stream-management UI
Technical summary
The vulnerability exists in RabbitMQ versions from 3.13.0 until 3.13.18 and 4.0.23 and 4.1.14 and 4.2.9 and 4.3.3. It allows an attacker to conduct Stored Cross-Site Scripting (XSS) attacks via TLS peer-certificate DN in the stream-management UI. This requires a non-default configuration: a stream TLS listener with 'verifypeer' and an attacker-obtainable trusted certificate with a malicious Distinguished Name (DN).
Defensive priority
Defenders should prioritize verifying and updating RabbitMQ versions to 3.13.18 or later, 4.0.23 or later, 4.1.14 or later, 4.2.9 or later, or 4.3.3 or later. They should also review and restrict access to the stream-management UI and ensure that only trusted certificates are used.
Recommended defensive actions
- Verify and update RabbitMQ to version 3.13.18 or later, 4.0.23 or later, 4.1.14 or later, 4.2.9 or later, or 4.3.3 or later
- Review and restrict access to the stream-management UI
- Ensure only trusted certificates are used
- Confirm whether affected RabbitMQ deployments exist in managed environments and assign an owner for follow-up.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and NVD vulnerability detail provide information on the vulnerability, its impact, and fixed versions. However, the corpus does not establish versions, exploitation, impact, or remediation beyond provided official sources.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-67239 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-67239
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-67239 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-67239
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.9
-
Source reference
Unverified legacy reference
URL: https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.3.3
-
Source reference
Unverified legacy reference
URL: https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-xm9p-57xv-vxwc
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.