What is CVE-2026-24329?
A vulnerability in WildFly Core (CVE-2026-24329) allows an authenticated administrative user to inject a malformed payload into the 'Inet Address' field via the Management Model, causing an unrecoverable server crash. The payload is persisted into the standalone.xml configuration file, making the denial of service permanent after a restart.
Azərbaycanca: WildFly serverinin idarəetmə modelində aşkar edilmiş boşluq (CVE-2026-24329) autentifikasiya olunmuş inzibatçıya 'Inet Address' sahəsinə zərərli yük yeritməklə serveri çökdürməyə imkan verir. Bu yük `standalone.xml` konfiqurasiya faylına yazılaraq serveri bərpaolunmaz hala gətirir, istismar üçün inzibati giriş tələb olunur.
FAQ2
What privilege level is required to exploit CVE-2026-24329?
An authenticated administrative access is required for exploitation.
Why does this vulnerability cause an unrecoverable denial of service in WildFly?
Because the malformed payload is persisted into the standalone.xml configuration file, making the crash permanent even after a restart.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.