CVE-2026-24457
An unsafe parsing of OpenMQ's configuration, allows a remote attacker to read arbitrary files from a MQ Broker's server. A full exploitation could read unauthorized files of the OpenMQ’s host OS. In some scenarios RCE could be achieved.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/24xxx/CVE-2026-24457.json, https://nvd.nist.gov/vuln/detail/CVE-2026-24457, https://gitlab.eclipse.org/security/cve-assignment/-/issues/84, https://github.com/eclipse-ee4j/openmq