PT-2026-22725 · Eclipse · Eclipse Openmq
Camilo G
+1
·
Published
2026-03-03
·
Updated
2026-03-03
·
CVE-2026-22886
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Eclipse OpenMQ (affected versions not specified)
Description
Eclipse OpenMQ includes a TCP-based management service (
imqbrokerd) that requires authentication by default. The product is shipped with a default administrative account (admin/admin) and does not enforce a mandatory password change upon first use. The server continues to accept the default password indefinitely after the initial successful login, without any warning or enforcement. An attacker with access to the service port could authenticate as an administrator and gain full control of the protocol’s administrative features.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Eclipse Openmq