CVE-2026-24457CRITICAL 9.1EPSS p48.9%

CVE-2026-24457CVE-2026-24457

eclipse / openmq

Description

An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQ Broker's server. A full exploitation could read unauthorized files of the OpenMQ’s host OS. In some scenarios RCE could be achieved. This is fixed in OpenMQ 6.5.2, 6.9.0, and in GlassFish 7.0.26, 7.1.1, and 8.0.2.

Scoring

CVSS 3.19.1 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
EPSS0.64% probability of exploitation · percentile 48.9% · 2026-10-06T12:00:23Z
Published2026-03-05
Last modified2026-08-05

Underlying weaknesses· 2

CWE-22CWE-27

References

  1. https://gitlab.eclipse.org/security/cve-assignment/-/issues/84

2

TypeTargetConfidenceTier
WeaknessImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')cwe-220%live
WeaknessPath Traversal: 'dir/../../filename'cwe-270%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-44839
CVE
Apache ActiveMQ Deserialization of Untrusted Data Vulnerability
CVE
CVE-2026-43533
CVE
Apache RocketMQ Command Execution Vulnerability
CVE
CVE-2026-22886
CVE
CVE-2026-25112
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.