CVE-2026-24329
Wildfly-core: wildfly core: denial of service via malformed payload injection by an authenticated administrative user.
Record summary
CVE-2026-24329 has a selected CVSS score of 4.9 (medium).
Description
A flaw was found in wildfly-core. A remote user authenticated as an administrative user can inject a malformed payload into the Inet Address field through the Management Model. This injection causes the server to crash and become unrecoverable, as the payload is written into the standalone.xml configuration file. Manual intervention is required to restore server operation, leading to a denial of service.
Exploitation context
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 12, 2026 · Source: CVE List
Affected products and versions
6| Product | Source | Version range | Status |
|---|---|---|---|
Default status: affected | CVE List | Version data not supplied | |
Red Hat JBoss Enterprise Application Platform 7Browse Red Hat / Red Hat JBoss Enterprise Application Platform 7wildfly-core-securityDefault status: affected | CVE List | Version data not supplied | |
Red Hat JBoss Enterprise Application Platform 8Browse Red Hat / Red Hat JBoss Enterprise Application Platform 8wildfly-core-securityDefault status: affected | CVE List | Version data not supplied | |
Red Hat JBoss Enterprise Application Platform Expansion PackBrowse Red Hat / Red Hat JBoss Enterprise Application Platform Expansion Packwildfly-core-securityDefault status: affected | CVE List | Version data not supplied | |
Default status: affected | CVE List | Version data not supplied | |
Default status: affected | CVE List | Version data not supplied | |