Security Advisory

CVE-2026-24457

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-03-05 16:27:30
Last updated 2026-08-05 08:00:11
Assigner eclipse
CVSS score 9.1
State PUBLISHED

Description

An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQ Broker's server. A full exploitation could read unauthorized files of the OpenMQ’s host OS. In some scenarios RCE could be achieved. This is fixed in OpenMQ 6.5.2, 6.9.0, and in GlassFish 7.0.26, 7.1.1, and 8.0.2.