{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-24457", "assignerOrgId": "e51fbebd-6053-4e49-959f-1b94eeb69a2c", "state": "PUBLISHED", "assignerShortName": "eclipse", "dateReserved": "2026-01-23T11:07:26.456Z", "datePublished": "2026-03-05T16:27:30.984Z", "dateUpdated": "2026-08-05T08:00:11.450Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "e51fbebd-6053-4e49-959f-1b94eeb69a2c", "shortName": "eclipse", "dateUpdated": "2026-08-05T08:00:11.450Z" }, "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-22", "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')", "type": "CWE" } ] }, { "descriptions": [ { "lang": "en", "cweId": "CWE-27", "description": "CWE-27 Path Traversal: 'dir/../../filename'", "type": "CWE" } ] } ], "affected": [ { "vendor": "Eclipse Foundation", "product": "Eclipse OpenMQ", "versions": [ { "status": "affected", "version": "0", "lessThan": "6.5.2", "versionType": "semver" }, { "status": "affected", "version": "6.6.0", "lessThan": "6.9.0", "versionType": "semver" } ], "defaultStatus": "unaffected" }, { "vendor": "Eclipse Foundation", "product": "Eclipse GlassFish", "versions": [ { "status": "affected", "version": "0", "lessThan": "7.0.26", "versionType": "semver" }, { "status": "affected", "version": "7.1.0", "lessThan": "7.1.1", "versionType": "semver" }, { "status": "affected", "version": "8.0.0", "lessThan": "8.0.2", "versionType": "semver" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQ Broker's server. A full exploitation could read unauthorized files of the OpenMQ’s host OS. In some scenarios RCE could be achieved. This is fixed in OpenMQ 6.5.2, 6.9.0, and in GlassFish 7.0.26, 7.1.1, and 8.0.2.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "

An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQ Broker's server. A full exploitation could read unauthorized files of the OpenMQ’s host OS. In some scenarios RCE could be achieved. This is fixed in OpenMQ 6.5.2, 6.9.0, and in GlassFish 7.0.26, 7.1.1, and 8.0.2.

" } ] } ], "references": [ { "url": "https://gitlab.eclipse.org/security/cve-assignment/-/issues/84" } ], "metrics": [ { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV3_1": { "version": "3.1", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH", "baseSeverity": "CRITICAL", "baseScore": 9.1, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" } } ], "credits": [ { "lang": "en", "value": "Camilo G. AkA Dedalo (DeepSecurity Perú)", "type": "finder" } ], "source": { "discovery": "UNKNOWN" }, "x_generator": { "engine": "Vulnogram 1.0.4" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-03-06T16:00:31.715526Z", "id": "CVE-2026-24457", "options": [ { "Exploitation": "none" }, { "Automatable": "yes" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-03-06T16:11:32.915Z" } } ] } }