CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-24457

Critical · CVSS 9.1
CVSS
9.1
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-22, CWE-27, CWE-22

Description

An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQ Broker's server. A full exploitation could read unauthorized files of the OpenMQ’s host OS. In some scenarios RCE could be achieved. This is fixed in OpenMQ 6.5.2, 6.9.0, and in GlassFish 7.0.26, 7.1.1, and 8.0.2.

References

Status: profiled · ingested 2026-08-05T12:00:56.000Z