VYPR
Critical severity9.8NVD Advisory· Published Mar 3, 2026· Updated Apr 9, 2026

CVE-2026-22886

CVE-2026-22886

Description

OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product ships with a default administrative account (admin/ admin) and does not enforce a mandatory password change on first use. After the first successful login, the server continues to accept the default password indefinitely without warning or enforcement.

In real-world deployments, this service is often left enabled without changing the default credentials. As a result, a remote attacker with access to the service port could authenticate as an administrator and gain full control of the protocol’s administrative features.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Eclipse/Openmq2 versions
    cpe:2.3:a:eclipse:openmq:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:eclipse:openmq:*:*:*:*:*:*:*:*
    • (no CPE)

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.