In brief: Two access-control flaws in RabbitMQ allow attackers to exfiltrate OAuth secrets and bypass tenant isolation.
Two access-control vulnerabilities have been discovered in RabbitMQ that enable disclosure of OAuth secrets and a breach of tenant boundaries. This puts multi-tenant deployments at significant risk.
The security research team at Miggo has disclosed two access-control flaws in the RabbitMQ message broker software. The first vulnerability allows OAuth client secrets to be extracted from the broker. The second flaw enables attackers to cross tenant boundaries and disclose queue metadata from other tenants.
For enterprise environments, this presents a substantial risk, as RabbitMQ is frequently deployed for critical messaging infrastructure. With access to OAuth secrets, attackers can authenticate as legitimate clients and gain unauthorized access to systems. Bypassing tenant isolation in multi-tenant scenarios endangers the segregation of sensitive data between different organizational units or customers.
CISOs should examine affected RabbitMQ instances and deploy patched versions as quickly as possible. Particular attention should be given to multi-tenant deployments and systems that use OAuth authentication.
Source: thehackernews.com · Published 14 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.7.3.