CVE-2026-24457: Path Traversal
An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQ Broker's server. A full exploitation could read unauthorized files of the OpenMQ’s host OS. In some scenarios RCE could be achieved. This is fixed in OpenMQ 6.5.2, 6.9.0, and in GlassFish 7.0.26, 7.1.1, and 8.0.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenMQto a version that resolves this vulnerability.Fixed in 6.5.2 - Upgrade
Upgrade
OpenMQto a version that resolves this vulnerability.Fixed in 6.9.0 - Upgrade
Upgrade
GlassFishto a version that resolves this vulnerability.Fixed in 7.0.26 - Upgrade
Upgrade
GlassFishto a version that resolves this vulnerability.Fixed in 7.1.1 - Upgrade
Upgrade
GlassFishto a version that resolves this vulnerability.Fixed in 8.0.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24457?
CVE-2026-24457 is considered a critical vulnerability due to its potential for remote code execution and unauthorized file access.
How do I fix CVE-2026-24457?
To fix CVE-2026-24457, update Eclipse Open Message Queue to version 6.5.2 or later.
What types of attacks can be performed using CVE-2026-24457?
CVE-2026-24457 allows remote attackers to read arbitrary files and potentially achieve remote code execution on the server.
Which versions of Eclipse Open Message Queue are affected by CVE-2026-24457?
Eclipse Open Message Queue versions up to and including 6.5.1 are affected by CVE-2026-24457.
How can CVE-2026-24457 impact system security?
CVE-2026-24457 can significantly compromise system security by enabling unauthorized file access and possible remote code execution.