CVE-2026-24457CWE-22CWE-27path-traversal

CVE-2026-24457

Critical · published March 6, 2026

CVSS v3.1
9.1
EPSS
1%
Percentile
47.2
In the wild
Unconfirmed
What it is

An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQ Broker's server. A full exploitation could read unauthorized files of the OpenMQ’s host OS. In some scenarios RCE could be achieved. This is fixed in OpenMQ 6.5.2, 6.9.0, and in GlassFish 7.0.26, 7.1.1, and 8.0.2.

The record
Technical detail
CVSS v3.1
9.1 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CVSS v4.0
Not supplied
EPSS
0.00616 · 47.2th percentile
Weaknesses
CWE-22 · Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'); CWE-27 · Path Traversal: 'dir/../../filename'
Published
2026-03-06T00:16Z
Affected products (1)
ProductVersionsFixed in
eclipse/openmq≤ 6.5.1
References (1)
EPSS history
Timeline
  • 05 MAR 16:27Z
    An unsafe parsing of OpenMQ's configuration, allows a remote attacker to read arbitrary files from a MQ Broker's server
    cvelistv5