AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-24329

MEDIUM · CVSS 4.9 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

A vulnerability in wildfly-core allows an authenticated remote user with administrative privileges to inject a malformed payload into the Inet Address field via the Management Model, resulting in a server crash and unrecoverable state. This leads to a denial of service, requiring manual intervention to restore functionality. Organizations using wildfly-core, particularly those with administrative access exposed, should prioritize addressing this issue to mitigate potential service disruptions.

CVE
CVE-2026-24329
Severity
MEDIUM
CVSS
4.9
EPSS
0.34%

Original NVD Description

A flaw was found in wildfly-core. A remote user authenticated as an administrative user can inject a malformed payload into the Inet Address field through the Management Model. This injection causes the server to crash and become unrecoverable, as the payload is written into the standalone.xml configuration file. Manual intervention is required to restore server operation, leading to a denial of service.