CRITICAL🇵🇱 Wersja polska

CVE-2026-22886

CVSS 9.8v3.1pub. 2026-03-03upd. 2026-04-09

OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product ships with a default administrative account (admin/ admin) and does not enforce a mandatory password change on first use. After the first successful login, the server continues to accept the default password indefinitely without warning or enforcement. In real-world deployments, this service is often left enabled without changing the default credentials. As a result, a remote attacker with access to the service port could authenticate as an administrator and gain full control of the protocol’s administrative features.

🤖 AI Analysis
How it works

The management service based on the TCP protocol (imqbrokerd) is enabled by default and requires authentication, however the product is shipped with a predefined administrator account with credentials admin/admin. The system does not enforce a password change on first login or at any later time. After the first successful login, the server accepts the default password indefinitely, without warnings or mechanisms forcing its change. In practical deployments, this service is often left enabled without modification of the default authentication credentials.

Impact

An attacker with network access to the service port can authenticate as an administrator and gain full control over the administrative functions of the OpenMQ broker, which may lead to violations of confidentiality, integrity, and system availability.

Mitigation & patch

The default administrator account password (admin/admin) should be immediately changed to a strong, unique password. Patches available from the vendor should be applied according to the references. Additionally, it is recommended to restrict network access to the imqbrokerd service port only to trusted hosts using a firewall and to audit all deployments for the use of default login credentials.

Who is affected

Eclipse OpenMQ — versions indicated in vendor references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Eclipse Openmq

    APP
    Eclipse
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-24457CRITICAL9.1PL ✓same product

Path traversal w Eclipse OpenMQ — odczyt plików i potencjalny RCE

CVE-2026-12605CRITICAL9.6PL ✓same vendor

Eclipse GlassFish: CSRF+SSRF w DownloadServlet umożliwia przejęcie domeny

CVE-2026-60007CRITICAL9.1PL ✓same vendor

Eclipse Milo: padding oracle w uwierzytelnianiu OPC-UA umożliwia odzyskanie hasła

CVE-2026-2586CRITICAL9.1PL ✓same vendor

RCE w konsoli administracyjnej Eclipse GlassFish

CVE-2026-2587CRITICAL9.6PL ✓same vendor

RCE poprzez wstrzyknięcie Expression Language w Eclipse GlassFish