CVE-2026-27446
CRITICALMissing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker can use the Core protocol to force a target broker to establish an outbound Core federation connection to an attacker-controlled rogue broker. This could potentially result in message injection into any queue and/or message exfiltration from any queue
- Affected
- >=2.11.0,<=2.44.0
- Fixed in
- not stated
- Weakness
- CWE-306
- Published
- 2026-03-04
- Source
- NVD
NVDMITREreferencereferencereferencereferencereferencereferencereferencereferencereferencereference