Vulnerabilities (CVE)

Filtered by vendor Eclipse Subscribe
Filtered by product Openmq
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-24457 1 Eclipse 1 Openmq 2026-04-15 N/A 9.1 CRITICAL
An unsafe parsing of OpenMQ's configuration, allows a remote attacker to read arbitrary files from a MQ Broker's server. A full exploitation could read unauthorized files of the OpenMQ’s host OS. In some scenarios RCE could be achieved.
CVE-2026-22886 1 Eclipse 1 Openmq 2026-04-09 N/A 9.8 CRITICAL
OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product ships with a default administrative account (admin/ admin) and does not enforce a mandatory password change on first use. After the first successful login, the server continues to accept the default password indefinitely without warning or enforcement. In real-world deployments, this service is often left enabled without changing the default credentials. As a result, a remote attacker with access to the service port could authenticate as an administrator and gain full control of the protocol’s administrative features.