Bug 2444320 (CVE-2026-27446)

Summary: CVE-2026-27446 org.apache.artemis:artemis-server: org.apache.activemq:artemis-server: Apache Artemis, Apache ActiveMQ Artemis: Message injection and exfiltration due to missing authentication
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: anthomas, aschwart, asoldano, aszczucz, ataylor, bbaranow, bmaxwell, boliveir, brian.stansberry, bstansbe, darran.lofthouse, dbruscin, dhanak, dlofthou, dosoudil, drichtar, drosa, ehelms, fjuma, fmariani, ggainey, gmalinko, ibek, istudens, ivassile, iweiss, janstey, jrokos, juwatts, jwon, kvanderr, kverlaen, mcarlett, mhulan, mnovotny, mosmerov, mposolda, msvehla, nmoumoul, nwallace, osousa, pberan, pbizzarr, pcreech, pdelbell, pesilva, pjindal, pmackay, rchan, rmartinc, rstancel, rstepani, sausingh, sdawley, smaestri, smallamp, ssilvert, sthorger, tcunning, thjenkin, tmalecek, tom.jenkinson, vdosoudi, vmuzikar, yfang
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Apache Artemis and Apache ActiveMQ Artemis. An unauthenticated remote attacker can exploit a missing authentication for critical function vulnerability by using the Core protocol. This allows the attacker to force a target broker to establish an outbound Core federation connection to an attacker-controlled rogue broker. The primary consequence is the potential for message injection into any queue and/or message exfiltration from any queue via the rogue broker.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-03-04 07:05:15 UTC
Affected versions:

- Apache Artemis (org.apache.artemis:artemis-server) 2.50.0 through 2.51.0
- Apache ActiveMQ Artemis (org.apache.activemq:artemis-server) 2.11.0 through 2.44.0

Description:

Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker can use the Core protocol to force a target broker to establish an outbound Core federation connection to an attacker-controlled rogue broker. This could potentially result in message injection into any queue and/or message exfiltration from any queue via the rogue broker. This impacts environments that allow both:

- incoming Core protocol connections from untrusted sources to the broker

- outgoing Core protocol connections from the broker to untrusted targets

This issue affects:

- Apache Artemis from 2.50.0 through 2.51.0

- Apache ActiveMQ Artemis from 2.11.0 through 2.44.0.

Users are recommended to upgrade to Apache Artemis version 2.52.0, which fixes the issue.

The issue can be mitigated by either of the following:

- Remove Core protocol support from any acceptor receiving connections from untrusted sources. Incoming Core protocol connections are supported by default via the "artemis" acceptor listening on port 61616. See the "protocols" URL parameter configured for the acceptor. An acceptor URL without this parameter supports all protocols by default, including Core.

- Use two-way SSL (i.e. certificate-based authentication) in order to force every client to present the proper SSL certificate when establishing a connection before any message protocol handshake is attempted. This will prevent unauthenticated exploitation of this vulnerability.

Credit:

Hardik Mehta <me...> (finder)

References:

https://artemis.apache.org
https://www.cve.org/CVERecord?id=CVE-2026-27446

Comment 3 errata-xmlrpc 2026-03-05 21:59:36 UTC
This issue has been addressed in the following products:

  Red Hat AMQ Broker 7.12.6

Via RHSA-2026:3955 https://access.redhat.com/errata/RHSA-2026:3955

Comment 4 errata-xmlrpc 2026-03-06 06:15:10 UTC
This issue has been addressed in the following products:

  Red Hat AMQ Broker 7.13.4

Via RHSA-2026:3957 https://access.redhat.com/errata/RHSA-2026:3957

Comment 5 errata-xmlrpc 2026-05-14 16:56:34 UTC
This issue has been addressed in the following products:

  Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14

Via RHSA-2026:17668 https://access.redhat.com/errata/RHSA-2026:17668

Comment 6 errata-xmlrpc 2026-05-18 12:12:33 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 8.1

Via RHSA-2026:18059 https://access.redhat.com/errata/RHSA-2026:18059

Comment 7 errata-xmlrpc 2026-05-18 12:19:06 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9

Via RHSA-2026:18055 https://access.redhat.com/errata/RHSA-2026:18055

Comment 8 errata-xmlrpc 2026-05-18 12:22:01 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8

Via RHSA-2026:18054 https://access.redhat.com/errata/RHSA-2026:18054

Comment 10 errata-xmlrpc 2026-08-11 16:36:26 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7

Via RHSA-2026:53644 https://access.redhat.com/errata/RHSA-2026:53644

Comment 11 errata-xmlrpc 2026-08-11 17:41:22 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.4.25

Via RHSA-2026:53806 https://access.redhat.com/errata/RHSA-2026:53806

Comment 12 Jon Orris 2026-09-17 17:46:22 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9

Via RHSA-2026:53646 https://access.redhat.com/errata/RHSA-2026:53646

Comment 13 Jon Orris 2026-09-17 17:48:00 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8

Via RHSA-2026:53645 https://access.redhat.com/errata/RHSA-2026:53645