CVE-2026-24457
9.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Summary
An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQ Broker's server. A full exploitation could read unauthorized files of the OpenMQ’s host OS. In some scenarios RCE could be achieved. This is fixed in OpenMQ 6.5.2, 6.9.0, and in GlassFish 7.0.26, 7.1.1, and 8.0.2.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Eclipse Foundation | Eclipse OpenMQ | 0 < 6.5.2 | affected |
| Eclipse Foundation | Eclipse OpenMQ | 6.6.0 < 6.9.0 | affected |
| Eclipse Foundation | Eclipse GlassFish | 0 < 7.0.26 | affected |
| Eclipse Foundation | Eclipse GlassFish | 7.1.0 < 7.1.1 | affected |
| Eclipse Foundation | Eclipse GlassFish | 8.0.0 < 8.0.2 | affected |
Weaknesses
- CWE-22: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CWE-27: CWE-27 Path Traversal: 'dir/../../filename'
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.