CVE-2026-24457Disclosure(eclipse / openmq)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQ Broker's server. A full exploitation could read unauthorized files of the OpenMQ’s host OS. In some scenarios RCE could be achieved. This is fixed in OpenMQ 6.5.2, 6.9.0, and in GlassFish 7.0.26, 7.1.1, and 8.0.2.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-27

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openmq

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-05); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
openmq

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-05: 2Mentions · 2026-03-08: 1Technical Details · 2026-03-05: 2Technical Details · 2026-03-08: 103-0503-08
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-052
Disclosure2
2026-03-081
General1
Full discourse3 posts
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-24457: CRITICAL] Unsafe parsing in OpenMQ config allows remote attackers to read files on server leading to unauthorized access or even remote code execution. #CyberSecurity#cve,CVE-2026-24457,#cybersecurity https://cvefind.com/CVE-2026-24457

    Post summary

    The post announces a critical CVE in OpenMQ that permits remote attackers to read files and potentially execute code, providing key technical details without any fix or active exploitation evidence.

    0001051
    598 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24457 An unsafe parsing of OpenMQ's configuration, allows a remote attacker to read arbitrary files from a MQ Broker's server. A full exploitation could read unauthorized f… https://www.cve.org/CVERecord?id=CVE-2026-24457

    Post summary

    The post announces CVE-2026-24457, noting unsafe parsing in OpenMQ that lets a remote attacker read arbitrary files from the broker.

    00010116
    56.6K followersView on X
  • The Hacker Wire@TheHackerWire
    General

    🔴 CVE-2026-24457 - Critical An unsafe parsing of OpenMQ's configuration, allows a remote attacker to read arbitrary files from a MQ Broker's server. A full exploitation could read unauthorized files of the OpenMQ’... https://www.thehackerwire.com/vulnerability/CVE-2026-24457/ https://t.co/Kcw2oksKmM

    Post summary

    The tweet announces CVE‑2026‑24457, highlighting that unsafe parsing of OpenMQ configuration can let remote attackers read arbitrary files, but it offers no evidence of active exploitation, a PoC, or a patch.

    0000039
    130 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appeclipseopenmq---

Explore more