What is CVE-2026-24330?
CVE-2026-24330 is a vulnerability found in wildfly-core. A remote attacker with 'deployer' authentication can import and deploy a malicious archive from an untrusted source. This is achieved by crafting a Java project that leverages WildFly libraries via an HTTP POST request.
Azərbaycanca: CVE-2026-24330, WildFly nüvəsində aşkar edilmiş boşluqdur. 'Deployer' hesabı ilə autentifikasiya olunmuş uzaqdan hücumçu, etibarsız mənbədən zərərli arxiv faylı idxal edib yerləşdirə bilər. Bu, WildFly kitabxanalarından istifadə edərək xüsusi HTTP POST sorğusu ilə həyata keçirilir.
FAQ2
What level of authentication does an attacker need to exploit CVE-2026-24330?
The attacker must be authenticated with a 'deployer' account to exploit the vulnerability.
How does an attacker deploy the malicious archive using WildFly libraries?
The attacker crafts a Java project that leverages WildFly libraries and carries out the deployment via an HTTP POST request.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.