THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-24457 (CRITICAL 9.1) — An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQ Broker's server. A full exploitation could read unauthorized files of the OpenMQ’s host OS. In some scenarios RCE could be achieved. This i

[NVD] CVE-2026-24457 (CRITICAL 9.1) — An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQ Broker's server. A full exploitation could read unauthorized files of the OpenMQ’s host OS. In some scenarios RCE could be achieved. This i

lownvdPublished 2026-03-05

CVE-2026-24457 CVSS: 9.1 CRITICAL Published: 2026-03-05T19:16:02.780

An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQ Broker's server. A full exploitation could read unauthorized files of the OpenMQ’s host OS. In some scenarios RCE could be achieved. This is fixed in OpenMQ 6.5.2, 6.9.0, and in GlassFish 7

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-24457