CVE-2026-24330: Unrestricted Upload of File with Dangerous Type in Red Hat Red Hat Fuse 7
CVE-2026-24330 is a vulnerability in wildfly-core affecting Red Hat Fuse 7, where an authenticated attacker with 'deployer' privileges can upload and deploy a malicious archive file via HTTP POST. This flaw could lead to further exploitation, including arbitrary file read vulnerabilities. The vulnerability requires authentication as a 'deployer' account and does not require user interaction. The CVSS score is 6.5 (medium severity).
AI Analysis
Technical Summary
This vulnerability in wildfly-core allows a remote attacker authenticated as a 'deployer' account to import and deploy a malicious archive file from an untrusted source. The attacker leverages WildFly libraries to craft a Java project that enables an HTTP POST request to upload and deploy the malicious archive. Successful exploitation could lead to arbitrary file read vulnerabilities. The vulnerability is rated moderate because it requires high privileges (authenticated deployer) and does not affect availability. The vulnerability is tracked as CVE-2026-24330 with a CVSS v3.1 score of 6.5.
Potential Impact
An attacker authenticated as a 'deployer' can deploy malicious archives, potentially leading to arbitrary file read vulnerabilities and compromise of confidentiality and integrity. There is no impact on availability. The attack vector is network-based with low complexity and no user interaction required. The vulnerability does not allow unauthenticated exploitation, limiting its impact to those with deployer privileges.
Mitigation Recommendations
No official patch or fix is currently confirmed. Mitigation involves restricting access to the 'deployer' account to authorized and trusted administrators only, implementing strong authentication policies, and limiting deployer permissions to prevent deployment of untrusted applications. WildFly management interfaces should not be exposed to untrusted networks, and only verified and signed applications should be permitted for deployment. If the 'deployer' role is not necessary, consider disabling or removing it. Configuration changes may require a service restart. Patch status is not yet confirmed — check the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2026-24330 for updates.
CVE-2026-24330: Unrestricted Upload of File with Dangerous Type in Red Hat Red Hat Fuse 7
Description
CVE-2026-24330 is a vulnerability in wildfly-core affecting Red Hat Fuse 7, where an authenticated attacker with 'deployer' privileges can upload and deploy a malicious archive file via HTTP POST. This flaw could lead to further exploitation, including arbitrary file read vulnerabilities. The vulnerability requires authentication as a 'deployer' account and does not require user interaction. The CVSS score is 6.5 (medium severity).
CVSS v3.1
Score 6.5medium
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in wildfly-core allows a remote attacker authenticated as a 'deployer' account to import and deploy a malicious archive file from an untrusted source. The attacker leverages WildFly libraries to craft a Java project that enables an HTTP POST request to upload and deploy the malicious archive. Successful exploitation could lead to arbitrary file read vulnerabilities. The vulnerability is rated moderate because it requires high privileges (authenticated deployer) and does not affect availability. The vulnerability is tracked as CVE-2026-24330 with a CVSS v3.1 score of 6.5.
Potential Impact
An attacker authenticated as a 'deployer' can deploy malicious archives, potentially leading to arbitrary file read vulnerabilities and compromise of confidentiality and integrity. There is no impact on availability. The attack vector is network-based with low complexity and no user interaction required. The vulnerability does not allow unauthenticated exploitation, limiting its impact to those with deployer privileges.
Mitigation Recommendations
No official patch or fix is currently confirmed. Mitigation involves restricting access to the 'deployer' account to authorized and trusted administrators only, implementing strong authentication policies, and limiting deployer permissions to prevent deployment of untrusted applications. WildFly management interfaces should not be exposed to untrusted networks, and only verified and signed applications should be permitted for deployment. If the 'deployer' role is not necessary, consider disabling or removing it. Configuration changes may require a service restart. Patch status is not yet confirmed — check the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2026-24330 for updates.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-01-22T03:12:39.123Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-24330","vendor":"Red Hat"}]
Threat ID: 6a7a92febf8831d53907dda3
Added to database: 08/11/2026, 03:11:58 UTC
Last enriched: 08/11/2026, 03:31:01 UTC
Last updated: 08/11/2026, 03:31:01 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.