Red HatCVE-2026-24329
Red Hat wildfly-core: denial of service
Medium4.9CVE-2026-24329 · Published Aug 11, 2026 · updated Aug 14, 2026
A flaw was found in wildfly-core. A remote user authenticated as an administrative user can inject a malformed payload into the Inet Address field through the Management Model. This injection causes the server to crash and become unrecoverable, as the payload is written into the standalone.xml configuration file. Manual intervention is required to restore server operation, leading to a denial of service.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Fuse 7 Product | all versions | No fix yet |
| Red Hat JBoss Enterprise Application Platform 7 Product | all versions | No fix yet |
| Red Hat JBoss Enterprise Application Platform 8 Product | all versions | No fix yet |
| Red Hat JBoss Enterprise Application Platform Expansion Pack Product | all versions | No fix yet |
| Red Hat Process Automation 7 Product | all versions | No fix yet |
| Red Hat Single Sign-On 7 Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-91
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 11 | Red Hat FreeIPA: improper authorization | High8.2 | No fix yet |
| Aug 11 | Red Hat search-v2-api. The authentication middleware: authentication bypass | High7.5 | No fix yet |
| Aug 11 | Red Hat acm-search-v2-api-rhel9.: information disclosure | Medium5.3 | No fix yet |
| Aug 11 | Red Hat insights-client.: information disclosure | High7.1 | No fix yet |
| Aug 11 | Red Hat insights-client. A compromised managed cluster: information disclosure | Medium6.8 | No fix yet |
| Aug 11 | Red Hat insights-client: secrets in logs | Medium6.3 | No fix yet |