---
id: CVE-2025-23368
title: A flaw was found in Wildfly Elytron integration
summary: >-
  A flaw was found in Wildfly Elytron integration. The component does not
  implement sufficient measures to prevent multiple failed authentication
  attempts within a short time frame, making it more susceptible to brute force
  attacks via CLI.
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-307
vendor: redhat
product: wildfly_core
affected:
  - wildfly_core < 31.0.3
  - data_grid = 8.0
  - jboss_enterprise_application_platform = 7.0.0
  - jboss_enterprise_application_platform = 8.0.0
patched:
  - wildfly_core 31.0.3
published: '2025-03-04'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T22:16:55.233'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-23368'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:18054'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:18055'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:18059'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:33371'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2025-23368'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2337621'
    label: secalert@redhat.com
  - url: 'https://www.gruppotim.it/it/footer/red-team.html'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-23368.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-23368'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-23368'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
  - cve.org
epss: 0.00867
epssPercentile: 0.5708
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2025-03-04T15:57:14.702481Z'
ingestedAt: '2026-06-30T03:49:03.444Z'
---

## Overview

A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.

## Affected

- `wildfly_core < 31.0.3`
- `data_grid = 8.0`
- `jboss_enterprise_application_platform = 7.0.0`
- `jboss_enterprise_application_platform = 8.0.0`

## Remediation

Upgrade past the affected range:

- `wildfly_core 31.0.3`

## Vendor advisories

- **RHSA-2026:33371** · Red Hat · fixed in: Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server · released 2026-06-30 · [advisory](https://access.redhat.com/errata/RHSA-2026:33371)
- **RHSA-2026:18054** · Red Hat · fixed in: Red Hat JBoss EAP 8.1 for RHEL 8 · released 2026-05-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:18054)
- **RHSA-2026:18055** · Red Hat · fixed in: Red Hat JBoss EAP 8.1 for RHEL 9 · released 2026-05-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:18055)
- **RHSA-2026:18059** · Red Hat · fixed in: Red Hat JBoss Enterprise Application Platform 8.1 · released 2026-05-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:18059)
- **Red Hat VEX** · Important · affected: Red Hat Data Grid 8, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat Process Automation 7, Red Hat Single Sign-On 7 · no fix planned: Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat Process Automation 7, Red Hat Single Sign-On 7, … · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-23368.json)
