CVE-2026-22886

OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product ships with a default administrative account (admin/ admin) and does not enforce a mandatory password change on first use. After the first successful login, the server continues to accept the default password indefinitely without warning or enforcement. In real-world deployments, this service is often left enabled without changing the default credentials. As a result, a remote attacker with access to the service port could authenticate as an administrator and gain full control of the protocol’s administrative features.
References
Link Resource
https://gitlab.eclipse.org/security/cve-assignment/-/issues/85 Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:eclipse:openmq:*:*:*:*:*:*:*:*

History

09 Apr 2026, 19:47

Type Values Removed Values Added
References () https://gitlab.eclipse.org/security/cve-assignment/-/issues/85 - Vendor Advisory, Issue Tracking () https://gitlab.eclipse.org/security/cve-assignment/-/issues/85 - Issue Tracking, Vendor Advisory
First Time Eclipse openmq
Eclipse
CPE cpe:2.3:a:elipse:openmq:*:*:*:*:*:*:*:* cpe:2.3:a:eclipse:openmq:*:*:*:*:*:*:*:*

02 Apr 2026, 20:27

Type Values Removed Values Added
CPE cpe:2.3:a:elipse:openmq:*:*:*:*:*:*:*:*
First Time Elipse openmq
Elipse
References () https://gitlab.eclipse.org/security/cve-assignment/-/issues/85 - () https://gitlab.eclipse.org/security/cve-assignment/-/issues/85 - Vendor Advisory, Issue Tracking
Summary
  • (es) OpenMQ expone un servicio de gestión basado en TCP (imqbrokerd) que por defecto requiere autenticación. Sin embargo, el producto se envía con una cuenta administrativa por defecto (admin/admin) y no impone un cambio de contraseña obligatorio en el primer uso. Después del primer inicio de sesión exitoso, el servidor continúa aceptando la contraseña por defecto indefinidamente sin advertencia ni imposición. En implementaciones del mundo real, este servicio a menudo se deja habilitado sin cambiar las credenciales por defecto. Como resultado, un atacante remoto con acceso al puerto del servicio podría autenticarse como administrador y obtener control total de las características administrativas del protocolo.

03 Mar 2026, 10:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-03 10:16

Updated : 2026-06-17 10:20


NVD link : CVE-2026-22886

Mitre link : CVE-2026-22886

CVE.ORG link : CVE-2026-22886


JSON object : View

Products Affected

eclipse

  • openmq
CWE
CWE-1391

Use of Weak Credentials

CWE-1392

Use of Default Credentials

CWE-1393

Use of Default Password