CVE-2026-24329

A flaw was found in wildfly-core. A remote user authenticated as an administrative user can inject a malformed payload into the Inet Address field through the Management Model. This injection causes the server to crash and become unrecoverable, as the payload is written into the standalone.xml configuration file. Manual intervention is required to restore server operation, leading to a denial of service.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-11 03:17

Updated : 2026-08-14 19:07


NVD link : CVE-2026-24329

Mitre link : CVE-2026-24329

CVE.ORG link : CVE-2026-24329


JSON object : View

Products Affected

No product.

CWE
CWE-91

XML Injection (aka Blind XPath Injection)