
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27446 is a Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis and Apache ActiveMQ Artemis that allows an unauthenticated remote attacker to force a target broker to establish an outbound Core federation connection to an attacker-controlled rogue broker, enabling message injection and exfiltration. It was disclosed on March 3, 2026 by researcher Hardik Mehta and published on March 4, 2026. Affected versions include Apache Artemis 2.50.0 through 2.51.0 and Apache ActiveMQ Artemis 2.11.0 through 2.44.0. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 9.3 (Critical) (Red Hat Advisory, oss-security).
The root cause is CWE-306 (Missing Authentication for Critical Function): the Apache Artemis Core protocol does not require authentication before processing federation connection requests, allowing any network-accessible client to send a specially crafted Core protocol message that instructs the broker to initiate an outbound federation connection to an attacker-specified endpoint. Exploitation requires two conditions to be simultaneously true: the broker must accept incoming Core protocol connections from untrusted sources (enabled by default on port 61616 via the "artemis" acceptor), and the broker must be permitted to make outgoing Core protocol connections to untrusted targets. No credentials, user interaction, or special privileges are required. The vulnerability was reported to the Apache security team by Hardik Mehta (oss-security, Red Hat Bugzilla).
A successful exploit allows an unauthenticated attacker to inject arbitrary messages into any queue on the target broker and/or exfiltrate messages from any queue by routing them through the attacker-controlled rogue broker. This results in high confidentiality impact (sensitive message content exposed), high integrity impact (malicious messages injected into business-critical queues), and potential availability disruption through message queue manipulation. In environments where the broker handles financial transactions, healthcare data, or other sensitive workloads, the blast radius extends to all consumers and producers connected to the compromised broker infrastructure (oss-security, Red Hat Bugzilla).
FederationDownstreamConfiguration or outbound federation link creation without corresponding administrative action.The primary remediation is to upgrade to Apache Artemis 2.52.0 or later, which fixes the vulnerability. For Apache ActiveMQ Artemis users, Red Hat has released patches via RHSA-2026:3955 (AMQ Broker 7.12.6), RHSA-2026:3957 (AMQ Broker 7.13.4), RHSA-2026:17668, RHSA-2026:18054, RHSA-2026:18055, and RHSA-2026:18059 for various Red Hat products. If immediate upgrade is not possible, apply one of two workarounds: (1) restrict the protocols URL parameter on any acceptor receiving untrusted connections to exclude the Core protocol (e.g., set protocols=AMQP or another non-Core protocol); or (2) enforce two-way SSL/TLS with certificate-based authentication on all acceptors so that unauthenticated clients cannot complete a connection before the message protocol handshake (oss-security, Red Hat Bugzilla).
The Apache security team (Justin Bertram) disclosed the vulnerability via the oss-security mailing list on March 3, 2026, rating it as "critical" severity. Red Hat's Product Security team (Yogesh Mittal) promptly followed up requesting timely CVE record publication and coordinated multiple errata releases across AMQ Broker and JBoss EAP products. Belgium's Centre for Cybersecurity (CCB) issued a warning advisory, and CISA published an ICS advisory (ICSA-26-134-09) referencing the vulnerability. Siemens also issued a product security advisory (SSA-085541) indicating impact on their products (CCB Belgium, CISA ICS Advisory, Siemens Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."