CVE-2026-27446
Apache Software Foundation Apache Artemis, Apache ActiveMQ Artemis, Red Hat AMQ Broker 7.12.6
Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker can use the Core protocol to force a target broker to establish an outbound Core federation connection to an attacker-controlled rogue broker. This could potentially result in message injection into any queue and/or message exfiltration from any queue via the rogue broker. This impacts environments that allow both: - incoming Core protocol connections from untrusted sources to the broker - outgoing Core protocol connections from the broker to un...
- CVSS
- 9.3
- EPSS
- 10.0% 95.1% percentile
- CISA KEV
- Not listed
- Published
- 2026.03.04