
Critical Access Control Flaws in RabbitMQ Could Leak OAuth Secrets and Enable Infrastructure Takeover
Cybersecurity researchers from Miggo’s security team disclosed two access control-related flaws in the RabbitMQ message broker service, which could enable attackers to leak OAuth client secrets, expose enterprise messaging infrastructure to takeover risks, and bypass tenant boundaries. The vulnerabilities specifically impact the broker’s confidential OAuth implementation and access control mechanisms. No CVE IDs, specific versions, or patch release dates were mentioned in the disclosed details. The flaws were reported by Miggo after discovery, though the exact timeline of disclosure remains unspecified. The impacts include potential unauthorized access to sensitive credentials and cross-tenant metadata exposure within affected RabbitMQ deployments.