CVE-2026-24457
An unsafe parsing of OpenMQ's configuration, allows a remote attacker to read arbitrary files from a MQ Broker's server. A full exploitation could read unauthorized files of the OpenMQ’s host OS. In some scenarios RCE could be achieved.
- Vendor
- Eclipse Foundation
- Product
- Eclipse OpenMQ
- Provider severity
- CRITICAL
- Conflicts
- 1