CVE-2026-24330Disclosure

LOWCVSS 6.5 · MEDIUM

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a malicious archive file from an untrusted source. This is achieved by leveraging WildFly libraries to craft a Java project that allows an HTTP POST request to upload and deploy the malicious archive. This could lead to further exploitation, such as arbitrary file read vulnerabilities.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-08-11: 4Technical Details · 2026-08-11: 308-11
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-24330 A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a malicious archive file from an untrusted source. T… https://www.cve.org/CVERecord?id=CVE-2026-24330

    Post summary

    A vulnerability in wildfly‑core permits authenticated deployer users to upload malicious archives; the post provides the flaw’s details but no exploitation evidence, PoC, or patch information.

    000101.0K
    57.9K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-24330 A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a malicious archive file from an untrusted source. T… https://www.cve.org/CVERecord?id=CVE-2026-24330 ----- Traducción: Se encontró una vu… http://infoflow.cloud`

    Post summary

    CVE-2026-24330 is a disclosed flaw in wildfly-core that allows remote authenticated attackers to deploy malicious archives; no exploitation or patch is reported.

    0000037
    97 followersView on X
  • SecNews@SecNews_GR
    Disclosure

    WildFly CVE-2026-24330: Ευπάθεια στην ανάπτυξη αρχείων https://secn.ws/rhqWt6

    Post summary

    The post announces a new WildFly vulnerability (CVE‑2026‑24330) affecting file deployment, but provides no proof of exploit, PoC, or patch details.

    00000196
    7.0K followersView on X
  • SecNews@SecNews_GR
    Disclosure

    WildFly CVE-2026-24330: Ευπάθεια στην ανάπτυξη αρχείων https://secn.ws/0fsi68

    Post summary

    The post announces CVE‑2026‑24330 as a file‑deployment vulnerability in WildFly but offers no further technical or mitigation details.

    00000163
    7.0K followersView on X

Explore more