PT-2026-22892 · Apache · Apache Artemis+1
Hardik Mehta
+1
·
Published
2026-03-04
·
Updated
2026-06-15
·
CVE-2026-27446
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Artemis versions 2.50.0 through 2.51.0
Apache ActiveMQ Artemis versions 2.11.0 through 2.44.0
Description
A missing authentication check for a critical function exists in Apache Artemis and Apache ActiveMQ Artemis. An unauthenticated remote attacker can leverage the Core protocol to force a broker to establish an outbound Core federation connection to a rogue broker controlled by the attacker. This could lead to message injection into any queue and/or message exfiltration from any queue through the rogue broker. The issue impacts environments that permit both incoming Core protocol connections from untrusted sources and outgoing Core protocol connections to untrusted targets.
Recommendations
Upgrade to Apache Artemis version 2.52.0.
Remove Core protocol support from any acceptor receiving connections from untrusted sources.
Use two-way SSL (certificate-based authentication) to require clients to present a valid SSL certificate before any message protocol handshake.
Fix
DoS
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Activemq Artemis
Apache Artemis