CVE-2026-22886

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/03/2026
Last modified:
09/04/2026

Description

OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires<br /> authentication. However, the product ships with a default administrative account (admin/<br /> admin) and does not enforce a mandatory password change on first use. After the first<br /> successful login, the server continues to accept the default password indefinitely without<br /> warning or enforcement.<br /> <br /> <br /> In real-world deployments, this service is often left enabled without changing the default<br /> credentials. As a result, a remote attacker with access to the service port could authenticate<br /> as an administrator and gain full control of the protocol’s administrative features.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:eclipse:openmq:*:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools