In brief: RabbitMQ access control vulnerabilities compromise OAuth authentication and multi-tenant isolation in message broker infrastructures.
Two security vulnerabilities in RabbitMQ enable attackers to exfiltrate OAuth client secrets and bypass isolation between tenants. The Miggo security group has identified and disclosed the weaknesses.
Security researchers from the Miggo security group have disclosed two access control vulnerabilities in the RabbitMQ message broker service. The first vulnerability enables exfiltration of the broker’s confidential OAuth client secrets. The second weakness results in circumvention of tenant boundaries, allowing attackers to access queue metadata of other tenants.
These vulnerabilities present significant risks: Compromising OAuth client secrets can lead to complete takeover of the enterprise messaging infrastructure. Attackers could authenticate as the broker itself and access all managed messages as well as underlying systems. Bypassing tenant isolation jeopardizes multi-tenant deployments, particularly in cloud environments where multiple independent organizations operate a shared RabbitMQ instance.
For CISOs with RabbitMQ deployments, disclosure of these access control vulnerabilities requires urgent review of their RabbitMQ versions and authentication configuration, as well as assessment of whether multi-tenant scenarios are affected. Updates should be applied promptly once available.
Source: thehackernews.com · Published 14 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.