Project Subscriptions
| Vendors | Products |
|---|---|
|
Redhat
Subscribe
|
Fuse 7
Subscribe
Jboss Enterprise Application Platform
Subscribe
Jboss Enterprise Application Platform Expansion Pack
Subscribe
Jboss Enterprise Bpms Platform
Subscribe
Jboss Fuse
Subscribe
Jbosseapxp
Subscribe
Process Automation
Subscribe
Red Hat Single Sign On
Subscribe
Single Sign On
Subscribe
Wildfly Core
Subscribe
|
No advisories yet.
Solution
No solution given by the vendor.
Workaround
To mitigate this vulnerability, restrict access to the 'deployer' account to only authorized and trusted administrators. Implement strong authentication policies for this account and consider limiting its permissions to prevent the deployment of untrusted applications. Ensure that the WildFly management interfaces are not exposed to untrusted networks and that only verified and signed applications are permitted for deployment. If the 'deployer' role is not strictly necessary, consider disabling or removing it. Changes to WildFly configuration may require a service restart to take effect.
Tue, 11 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat fuse 7
Redhat jboss Enterprise Application Platform Expansion Pack Redhat process Automation Redhat single Sign On Redhat wildfly Core |
|
| Vendors & Products |
Redhat fuse 7
Redhat jboss Enterprise Application Platform Expansion Pack Redhat process Automation Redhat single Sign On Redhat wildfly Core |
Tue, 11 Aug 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 11 Aug 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a malicious archive file from an untrusted source. This is achieved by leveraging WildFly libraries to craft a Java project that allows an HTTP POST request to upload and deploy the malicious archive. This could lead to further exploitation, such as arbitrary file read vulnerabilities. | |
| Title | Wildfly-core: wildfly: arbitrary file read via malicious archive deployment | |
| First Time appeared |
Redhat
Redhat jboss Enterprise Application Platform Redhat jboss Enterprise Bpms Platform Redhat jboss Fuse Redhat jbosseapxp Redhat red Hat Single Sign On |
|
| Weaknesses | CWE-434 | |
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform:7 cpe:/a:redhat:jboss_enterprise_application_platform:8 cpe:/a:redhat:jboss_enterprise_bpms_platform:7 cpe:/a:redhat:jboss_fuse:7 cpe:/a:redhat:jbosseapxp cpe:/a:redhat:red_hat_single_sign_on:7 |
|
| Vendors & Products |
Redhat
Redhat jboss Enterprise Application Platform Redhat jboss Enterprise Bpms Platform Redhat jboss Fuse Redhat jbosseapxp Redhat red Hat Single Sign On |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-11T16:05:24.210Z
Reserved: 2026-01-22T03:12:39.123Z
Link: CVE-2026-24330
Updated: 2026-08-11T16:05:20.968Z
Status : Received
Published: 2026-08-11T03:17:36.463
Modified: 2026-08-11T17:17:56.070
Link: CVE-2026-24330
OpenCVE Enrichment
Updated: 2026-08-11T14:20:11Z