Junglewise Threat Intelligence

CVE-2026-24457: Eclipse OpenMQ arbitrary file read via unsafe configuration parsing

CVE-2026-24457 · Severity: critical · CVSS 9.1 · Published 2026-03-05

Technologies: Payara Server. Vendors: Eclipse, Oracle.

Executive brief

Eclipse OpenMQ is a message broker component used in application servers to queue and deliver messages between services. An unsafe configuration parser allows remote attackers to read arbitrary files from the server's filesystem, potentially exposing sensitive application and system data. In some cases, this vulnerability could lead to remote code execution.

Technical details

This vulnerability stems from unsafe parsing of OpenMQ's configuration files, enabling a path traversal or similar file disclosure attack (CWE-22, CWE-27). The vulnerability is remotely exploitable from the network without requiring authentication or special preconditions. An attacker can leverage the misconfigured parser to read unauthorized files on the OpenMQ broker's filesystem, including host OS files, and potentially achieve remote code execution in certain scenarios. Patched versions are available: OpenMQ 6.5.2, 6.9.0, and integrated in GlassFish 7.0.26, 7.1.1, and 8.0.2.

Affected products

  • Eclipse OpenMQ <6.5.2 and <6.9.0
  • Oracle GlassFish <7.0.26, <7.1.1, <8.0.2
  • Payara Payara Server versions with bundled OpenMQ <6.5.2 and <6.9.0

Timeline

  • 2026-03-05: disclosed: Vulnerability published on NVD
  • 2026: patched: Patches released in OpenMQ 6.5.2, 6.9.0 and GlassFish 7.0.26, 7.1.1, 8.0.2

References