Fedora Account System
Red Hat Associate
Red Hat Customer
Pre-auth topology disclosure via Artemis CORE SUBSCRIBE_TOPOLOGY_V2 on channel0. CoreProtocolManager.LocalChannelHandler.handlePacket() processes topology subscriptions with zero authentication -- no getSecurityStore(), no subject validation. Contrasts with federation handler fixed via ARTEMIS-5928 (CVE-2026-27446). Vulnerable class: org.apache.activemq.artemis.core.protocol.core.impl.CoreProtocolManager - https://github.com/apache/activemq-artemis/blob/2.16.0/artemis-server/src/main/java/org/apache/activemq/artemis/core/protocol/core/impl/CoreProtocolManager.java - https://github.com/apache/activemq-artemis/blob/2.52.0/artemis-server/src/main/java/org/apache/activemq/artemis/core/protocol/core/impl/CoreProtocolManager.java Affected: All Artemis versions (2.16.0 through 2.52.0 and main) Fixed: No upstream fix available Related (different issue): CVE-2026-27446 (federation handler auth bypass only, fixed via ARTEMIS-5928)
This issue has been addressed in the following products: Red Hat AMQ Broker 7.14.1 Via RHSA-2026:66488 https://access.redhat.com/errata/RHSA-2026:66488
This issue has been addressed in the following products: Red Hat AMQ Broker 7.13.6 Via RHSA-2026:66545 https://access.redhat.com/errata/RHSA-2026:66545