Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2026-27446

Apache Artemis: unauthenticated Core client can force an outbound federation connection to a rogue broker

Technology

ActiveMQ Artemis

CVSS Score

9.8 / 10.0

Affected Versions

Apache Artemis 2.50.0 to 2.51.0; Apache ActiveMQ Artemis 2.11.0 to 2.44.0

Upstream Fix

2.52.0

Published

March 4, 2026

OSSeva Coverage

Fixed upstream

Description

Missing authentication for a critical function in the Core protocol lets an unauthenticated remote attacker make the broker open an outbound Core federation connection to a broker the attacker controls, which can then inject messages into, or read messages from, any queue. It needs incoming Core connections from untrusted sources and outgoing Core connections to untrusted targets. Apache rates it critical. Until the upgrade, the advisory lists three mitigations: remove Core from acceptors that untrusted clients reach, require two-way TLS, or deploy a Core interceptor that rejects downstream federation connect packets.

Upstream record: NVD · CVE.org

Is your ActiveMQ Artemis deployment affected?

If you're running Apache Artemis 2.50.0 to 2.51.0; Apache ActiveMQ Artemis 2.11.0 to 2.44.0, you need this patch. Book a discovery call to get covered.