External risk intelligence

RabbitMQ JWT Validation Bypass Via Forged JWKS

CVE advisorySeverity: CRITICAL (CVSS 9.2)

CVE-2026-67404

RabbitMQ is typically deployed as internal infrastructure for backend messaging services. The vulnerability requires a specific OAuth2 plugin configuration, an empty or unreadable CA bundle, and a successful man-in-the-middle position, making public internet exposure and exploitation unlikely in common deployments.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability in RabbitMQ affects messaging and streaming operations where the OAuth2 plugin is used without proper certificate verification. An attacker in a network man-in-the-middle position could potentially impersonate legitimate services, leading to the acceptance of unauthorized messages. The primary concern at this time is to determine if your environment uses RabbitMQ with the OAuth2 plugin and lacks a configured CA bundle.

  • Broker accepts forged security tokens.
  • Unchecked security tokens can bypass authentication.
  • Confirm if OAuth2 plugin and unverified tokens are used.

Attack Path

How an attacker could exploit the issue

An attacker positioned between the user and the RabbitMQ broker could exploit this vulnerability by intercepting and forging responses. If the OAuth2 plugin is enabled without a configured CA bundle, and the system's CA bundle is inaccessible, the broker may accept forged JSON Web Key Set (JWKS) responses. This allows the attacker to present arbitrary JSON Web Tokens (JWTs), potentially leading to unauthorized access or control.

  • Requires OAuth2 plugin and missing CA configuration.
  • Attacker forges JWKS response during connection.
  • Broker accepts arbitrary JWTs.

Live Threat

Current exploitation, exposure, and threat context

When the OAuth2 plugin is used without a configured CA bundle and the operating system's CA bundle is empty or unreadable, a man-in-the-middle attacker could potentially forge JWKS responses, leading RabbitMQ to accept arbitrary JWTs. This could impact the integrity of messages processed by the broker.

  • Broker's ability to validate JWTs.
  • Attacker intercepts network traffic.
  • Broker accepts malicious authentication.

Operational Fix

Recommended remediation, mitigation, and detection steps

The RabbitMQ platform or infrastructure team is likely responsible for managing this messaging broker. The first practical step is to identify all RabbitMQ instances, particularly those using the OAuth2 plugin without a configured CA bundle, and assess their exposure and business criticality to prioritize remediation efforts.

  • Platform or infrastructure teams own the issue.
  • Verify OAuth2 plugin and CA bundle configurations.
  • Plan remediation based on assessed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is RabbitMQ?

RabbitMQ is an open-source messaging broker used by developers to facilitate communication between distributed software components. It acts as a middleman for data, ensuring that messages are reliably queued and delivered between different applications, services, or microservices within an IT environment.

How does CVE-2026-67404 affect JWT validation?

This vulnerability involves Improper Certificate Validation (CWE-295). When the broker fails to find a Certificate Authority bundle, it defaults to accepting any credentials without verification. This allows the system to be tricked into trusting malicious JSON Web Tokens because it stops checking the digital signatures that prove the tokens are authentic.

Does my network traffic trigger this bug?

Not automatically. The vulnerability only triggers if three conditions are met: the OAuth2 plugin is enabled, no CA bundle is configured in RabbitMQ, and the system CA bundle is missing or unreadable. If you have properly configured SSL/TLS certificates and a valid CA bundle, the broker will correctly reject unverified traffic, and this flaw will not be triggered.

Is my RabbitMQ instance at risk?

Halo Surface Signal notes that while this is a critical flaw, risk depends on your deployment. Since RabbitMQ is often used for internal backend messaging, it is less common for it to be directly exposed to the public internet. You should focus your investigation on instances where the broker communicates over untrusted networks, as an attacker must achieve a man-in-the-middle position to exploit this.

How do I secure my RabbitMQ environment?

Begin by auditing your RabbitMQ configurations to confirm if the OAuth2 plugin is active and if a CA bundle is properly defined. If you identify vulnerable instances, upgrade the RabbitMQ software to one of the patched versions (3.13.15, 4.0.20, 4.1.11, 4.2.6, or 4.3.0 or later) as your primary step to resolve the underlying authentication logic issue.

References