Vulnerability Description
A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a malicious archive file from an untrusted source. This is achieved by leveraging WildFly libraries to craft a Java project that allows an HTTP POST request to upload and deploy the malicious archive. This could lead to further exploitation, such as arbitrary file read vulnerabilities.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://access.redhat.com/security/cve/CVE-2026-24330
- https://bugzilla.redhat.com/show_bug.cgi?id=2431939
FAQ
What is CVE-2026-24330?
CVE-2026-24330 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a malicious archive file from an untrusted source. This is achieved by leveraging Wild...
How severe is CVE-2026-24330?
CVE-2026-24330 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-24330?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.