CVE-2026-24330
Received Received - Intake

Authenticated File Upload Leading to Arbitrary File Read in WildFly Core

Vulnerability report for CVE-2026-24330, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: Red Hat, Inc.

Description

A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a malicious archive file from an untrusted source. This is achieved by leveraging WildFly libraries to craft a Java project that allows an HTTP POST request to upload and deploy the malicious archive. This could lead to further exploitation, such as arbitrary file read vulnerabilities.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
redhat wildfly_core *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in WildFly Core allows a remote attacker with deployer privileges to upload and deploy a malicious archive file from an untrusted source. The attacker crafts a Java project that sends an HTTP POST request to deploy the file, potentially leading to further exploitation like arbitrary file reads.

Detection Guidance

To detect this vulnerability, monitor WildFly server logs for unusual deployment activities, particularly HTTP POST requests from the 'deployer' account. Check for unexpected archive uploads or deployments from untrusted sources. Inspect network traffic for suspicious file upload patterns to WildFly management interfaces.

Impact Analysis

If exploited, this vulnerability could allow an attacker to read arbitrary files on the system, escalate privileges, or perform unauthorized actions. Systems using WildFly Core with deployer accounts are at risk of unauthorized file access or deployment of malicious code.

Compliance Impact

This vulnerability could lead to unauthorized data access or exfiltration, violating GDPR's data protection requirements or HIPAA's safeguards for protected health information. Compliance may be compromised if sensitive data is exposed due to exploitation.

Mitigation Strategies

Immediately restrict the 'deployer' account privileges to the minimum required. Disable remote deployment capabilities if not needed. Ensure all uploaded archives are scanned for malicious content before deployment. Update WildFly-core to the latest patched version as soon as available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-24330. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart