CVE-2026-57219 is a high-severity information disclosure vulnerability in RabbitMQ's management plugin. In affected releases, the obsolete HTTP endpoint GET /api/auth is reachable without authentication because its authorization logic permits anonymous access, and the handler that generates the response includes the configured OAuth 2 client secret when the broker is set up with management.oauth_client_secret. As a result, an unauthenticated remote attacker who can reach the RabbitMQ management interface can retrieve the broker's confidential OAuth client secret with a single request. The issue affects RabbitMQ deployments using the management plugin together with OAuth 2 configurations that rely on a confidential client secret, and it is fixed by removing the obsolete route in patched versions so the endpoint is no longer served.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information disclosure vulnerability in RabbitMQ Management where the obsolete /api/auth endpoint can be accessed anonymously and leaks the configured OAuth 2 client secret in the response.
An authentication-related information disclosure flaw in RabbitMQ's management plugin that exposes the OAuth client secret via the obsolete /api/auth endpoint, enabling attackers to obtain an administrator token and take full control of the broker.
High-severity RabbitMQ vulnerability that lets an unauthenticated attacker obtain an OAuth client secret via the management interface and potentially escalate to an administrative token.
An access control flaw in RabbitMQ where an obsolete HTTP API endpoint leaks the broker's OAuth client secret to an unauthenticated attacker, enabling administrator token acquisition and full broker takeover in affected configurations.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.