WildFly Core Remote Authenticated Deployment via Malicious Archive Upload
CVE-2026-24330 Published on August 11, 2026
Wildfly-core: wildfly: arbitrary file read via malicious archive deployment
A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a malicious archive file from an untrusted source. This is achieved by leveraging WildFly libraries to craft a Java project that allows an HTTP POST request to upload and deploy the malicious archive. This could lead to further exploitation, such as arbitrary file read vulnerabilities.
Vulnerability Analysis
CVE-2026-24330 is exploitable with network access, and requires user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.
Timeline
Reported to Red Hat.
Made public. 188 days later.
Weakness Type
What is an Unrestricted File Upload Vulnerability?
The software allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment.
CVE-2026-24330 has been classified to as an Unrestricted File Upload vulnerability or weakness.
Products Associated with CVE-2026-24330
Want to know whenever a new CVE is published for Red Hat products? stack.watch will email you.