CVE-2026-22886 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product ships with a default administrative acc…
Critical CVSS: 9.8

CVE-2026-22886

OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires
authentication. However, the product ships with a default administrative account (admin/
admin) and does not enforce a mandatory password change on first use. After the first
successful login, the server continues to accept the default password indefinitely without
warning or enforcement.


In real-world deployments, this service is often left enabled without changing the default
credentials. As a result, a remote attacker with access to the service port could authenticate
as an administrator and gain full control of the protocol’s administrative features.
Vendor
Elipse
Product
Openmq
CWE
CWE-1391
Yayın Tarihi
2026-03-03 10:16:06
Güncelleme
2026-04-02 20:27:34
Source Identifier
emo@eclipse.org
KEV Date Added
-

Kategoriler

Referanslar