CVE-2026-24457

An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQ Broker's server. A full exploitation could read unauthorized files of the OpenMQ’s host OS. In some scenarios RCE could be achieved. This is fixed in OpenMQ 6.5.2, 6.9.0, and in GlassFish 7.0.26, 7.1.1, and 8.0.2.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:eclipse:openmq:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-05 19:16

Updated : 2026-08-05 08:16


NVD link : CVE-2026-24457

Mitre link : CVE-2026-24457

CVE.ORG link : CVE-2026-24457


JSON object : View

Products Affected

eclipse

  • openmq
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-27

Path Traversal: 'dir/../../filename'