CVE-2026-24457: Eclipse Openmq

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQ Broker's server. A full exploitation could read unauthorized files of the OpenMQ’s host OS. In some scenarios RCE could be achieved. This is fixed in OpenMQ 6.5.2, 6.9.0, and in GlassFish 7.0.26, 7.1.1, and 8.0.2.

Affected products

  • Eclipse Openmq: up to and including 6.5.1

Published 2026-03-05. Last modified 2026-08-05.