CVE-2026-67237 | RabbitMQ up to 4.2.7/4.3.1 OAuth set_token_auth access_token cross site scripting

SecurityVulns

A vulnerability labeled as problematic has been found in RabbitMQ up to 4.2.7/4.3.1. The affected element is the function set_token_auth of the component OAuth. Executing a manipulation of the argument access_token can lead to cross site scripting.

This vulnerability is registered as CVE-2026-67237. It is possible to launch the attack remotely. No exploit is available.

The affected component should be upgraded.VulDB Recent EntriesRead More