CVE-2026-24457

Summary

An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQ Broker's server. A full exploitation could read unauthorized files of the OpenMQ’s host OS. In some scenarios RCE could be achieved. This is fixed in OpenMQ 6.5.2, 6.9.0, and in GlassFish 7.0.26, 7.1.1, and 8.0.2.

Affected Software

VendorProductVersion RangeStatus
Eclipse FoundationEclipse OpenMQ0 < 6.5.2affected
Eclipse FoundationEclipse OpenMQ6.6.0 < 6.9.0affected
Eclipse FoundationEclipse GlassFish0 < 7.0.26affected
Eclipse FoundationEclipse GlassFish7.1.0 < 7.1.1affected
Eclipse FoundationEclipse GlassFish8.0.0 < 8.0.2affected

Weaknesses

  • CWE-22: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
  • CWE-27: CWE-27 Path Traversal: 'dir/../../filename'

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References