Kritische Sicherheitslücke in OpenMQ: CVE-2026-22886 mit Verwaltungskonto-Schwachstelle
⚠️ CVE-Referenzen:
CVE-2026-22886
Zusammenfassung
OpenMQ bietet standardmäßig einen TCP-basierten Verwaltungsdienst an, der mit einem Standardadministratorkonto (admin/admin) ausgeliefert wird. Dieses Konto muss nicht zwangsläufig geändert werden, wodurch Angreifer sich als Administratoren authentifizieren und die vollen Verwaltungsfunktionen missbrauchen können. Mit einer Bewertung von 9.8 auf der CVE-Skala handelt es sich um eine kritische Sicherheitslücke, die in Produktivumgebungen dringend behoben werden sollte.
OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires
authentication. However, the product ships with a default administrative account (admin/
admin) and does not enforce a mandatory password change on first use. After the first
successful login, the server continues to accept the default password indefinitely without
warning or enforcement.
In real-world deployments, this service is often left enabled without changing the default
credentials. As a result, a remote attacker with access to the service port could authenticate
as an administrator and gain full control of the protocol’s administrative features.
Quelle: app.opencve.io