CVE-2026-27446
Apache Artemis: unauthenticated Core client can force an outbound federation connection to a rogue broker
Technology
ActiveMQ Artemis
CVSS Score
9.8 / 10.0
Affected Versions
Apache Artemis 2.50.0 to 2.51.0; Apache ActiveMQ Artemis 2.11.0 to 2.44.0
Upstream Fix
2.52.0
Published
March 4, 2026
OSSeva Coverage
Fixed upstream
Description
Missing authentication for a critical function in the Core protocol lets an unauthenticated remote attacker make the broker open an outbound Core federation connection to a broker the attacker controls, which can then inject messages into, or read messages from, any queue. It needs incoming Core connections from untrusted sources and outgoing Core connections to untrusted targets. Apache rates it critical. Until the upgrade, the advisory lists three mitigations: remove Core from acceptors that untrusted clients reach, require two-way TLS, or deploy a Core interceptor that rejects downstream federation connect packets.
Is your ActiveMQ Artemis deployment affected?
If you're running Apache Artemis 2.50.0 to 2.51.0; Apache ActiveMQ Artemis 2.11.0 to 2.44.0, you need this patch. Book a discovery call to get covered.