A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a malicious archive file from an untrusted source. This is achieved by leveraging WildFly libraries to craft a Java project that allows an HTTP POST request to upload and deploy the malicious archive. This could lead to further exploitation, such as arbitrary file read vulnerabilities.
Metrics
Affected Vendors & Products
References
History
Tue, 11 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat fuse 7
Redhat jboss Enterprise Application Platform Expansion Pack Redhat process Automation Redhat single Sign On Redhat wildfly Core |
|
| Vendors & Products |
Redhat fuse 7
Redhat jboss Enterprise Application Platform Expansion Pack Redhat process Automation Redhat single Sign On Redhat wildfly Core |
Tue, 11 Aug 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 11 Aug 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a malicious archive file from an untrusted source. This is achieved by leveraging WildFly libraries to craft a Java project that allows an HTTP POST request to upload and deploy the malicious archive. This could lead to further exploitation, such as arbitrary file read vulnerabilities. | |
| Title | Wildfly-core: wildfly: arbitrary file read via malicious archive deployment | |
| First Time appeared |
Redhat
Redhat jboss Enterprise Application Platform Redhat jboss Enterprise Bpms Platform Redhat jboss Fuse Redhat jbosseapxp Redhat red Hat Single Sign On |
|
| Weaknesses | CWE-434 | |
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform:7 cpe:/a:redhat:jboss_enterprise_application_platform:8 cpe:/a:redhat:jboss_enterprise_bpms_platform:7 cpe:/a:redhat:jboss_fuse:7 cpe:/a:redhat:jbosseapxp cpe:/a:redhat:red_hat_single_sign_on:7 |
|
| Vendors & Products |
Redhat
Redhat jboss Enterprise Application Platform Redhat jboss Enterprise Bpms Platform Redhat jboss Fuse Redhat jbosseapxp Redhat red Hat Single Sign On |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published: 2026-08-11T02:35:22.539Z
Updated: 2026-08-11T16:05:24.210Z
Reserved: 2026-01-22T03:12:39.123Z
Link: CVE-2026-24330
Updated: 2026-08-11T16:05:20.968Z
Status : Received
Published: 2026-08-11T03:17:36.463
Modified: 2026-08-11T17:17:56.070
Link: CVE-2026-24330