CVE-2026-24330: Wildfly-core: wildfly: arbitrary file read via malicious archive deployment

Published Jan 22, 2026
·
Updated

A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a malicious archive file from an untrusted source. This is achieved by leveraging WildFly libraries to craft a Java project that allows an HTTP POST request to upload and deploy the malicious archive. This could lead to further exploitation, such as arbitrary file read vulnerabilities.

Other sources

A remote user authenticated as ‘deployer’ account can import and deploy a malicious archive file from an untrusted source outside the intended control environment. In this specific case, the attacker leveraged WildFly (open source) libraries to craft a Java project that enabled them to perform an HTTP POST request to upload and deploy the malicious archive file from the untrusted source. In this particular scenario, the archive file is a WAR that contains a “read.jsp” page. Once the attacker uploads this file, they can leverage it to exploit other vulnerabilities, such as Arbitrary File Read, as dimostrated in this case.

Red Hat

Affected Software

1 affected component
WildFly wildfly-core

Event History

Jan 22, 2026
Data Sourced
via Red Hat·03:19 AM
DescriptionSeverityAffected Software
Aug 11, 2026
CVE Published
via MITRE·02:35 AM
Data Sourced
via MITRE·02:35 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-24330?

The severity of CVE-2026-24330 is ranked as medium with a score of 6.5.

2

How can CVE-2026-24330 be mitigated?

To mitigate CVE-2026-24330, ensure that deployer accounts are only used for trusted sources and implement strict validation on uploaded files.

3

What impact does CVE-2026-24330 have on systems?

CVE-2026-24330 allows a remote attacker to read arbitrary files on the server by deploying a malicious archive.

4

Is CVE-2026-24330 exploitable without authentication?

No, CVE-2026-24330 requires the attacker to be authenticated as a 'deployer' account to exploit the vulnerability.

5

What type of vulnerability is CVE-2026-24330 classified as?

CVE-2026-24330 is classified as a Malicious File Upload vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203