CVE-2026-24329
Received Received - Intake

WildFly Core Denial of Service via Malformed Payload Injection

Vulnerability report for CVE-2026-24329, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: Red Hat, Inc.

Description

A flaw was found in wildfly-core. A remote user authenticated as an administrative user can inject a malformed payload into the Inet Address field through the Management Model. This injection causes the server to crash and become unrecoverable, as the payload is written into the standalone.xml configuration file. Manual intervention is required to restore server operation, leading to a denial of service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
redhat wildfly_core *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-91 The product does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in WildFly Core allows an authenticated administrative user to inject a malformed payload into the Inet Address field through the Management Model. The payload corrupts the standalone.xml configuration file, causing the server to crash and become unrecoverable without manual intervention.

Detection Guidance

To detect this vulnerability, monitor the WildFly management interface (port 9990) for unusual administrative access attempts or malformed payloads in the Inet Address field. Check the standalone.xml configuration file for unexpected or corrupted entries. Review server logs for crashes or unrecoverable errors related to configuration parsing.

Impact Analysis

The impact is a denial of service where the server crashes and cannot be restored without manually editing the corrupted configuration file. This requires downtime and administrative effort to recover.

Compliance Impact

This vulnerability primarily causes a denial of service by crashing the WildFly server and corrupting its configuration file, requiring manual recovery. It does not directly expose or leak data, which is a key concern for GDPR or HIPAA compliance. However, the resulting service disruption could impact availability requirements under these regulations. The need for manual intervention may also delay incident response, potentially affecting compliance timelines.

Mitigation Strategies

Restrict network access to the WildFly management interface (e.g., port 9990) to trusted hosts only using firewall rules. Ensure only necessary administrative users have access. Regularly audit administrative accounts and monitor for unauthorized changes to the standalone.xml file.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-24329. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart