CVE-2026-27446Missing Authentication for Critical Function in Software Foundation Apache Activemq Artemis

Severity
9.3CRITICALNVD
EPSS
0.1%
top 66.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 4
Latest updateMar 24

Description

Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker can use the Core protocol to force a target broker to establish an outbound Core federation connection to an attacker-controlled rogue broker. This could potentially result in message injection into any queue and/or message exfiltration from any queue via the rogue broker. This impacts environments that allow both: - incoming Core protocol connectio

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:L

Affected Packages5 packages

NVDapache/activemq_artemis2.11.02.44.0
CVEListV5apache_software_foundation/apache_artemis2.50.02.51.0
NVDapache/artemis2.50.0
CVEListV5knime/knime_business_hub1.17.01.17.4+2

🔴Vulnerability Details

4
OSV
Apache Artemis and Apache ActiveMQ Artemis are Missing Authentication for Critical Functions2026-03-04
GHSA
Apache Artemis and Apache ActiveMQ Artemis are Missing Authentication for Critical Functions2026-03-04
OSV
CVE-2026-27446: Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis2026-03-04
CVEList
Apache Artemis, Apache ActiveMQ Artemis: Auth bypass for Core downstream federation2026-03-04

📋Vendor Advisories

2
Red Hat
Apache Artemis: KNIME Business Hub: Apache Artemis and KNIME Business Hub: Authentication bypass allows information disclosure and message injection.2026-03-24
Red Hat
org.apache.artemis:artemis-server: org.apache.activemq:artemis-server: Apache Artemis, Apache ActiveMQ Artemis: Message injection and exfiltration due to missing authentication2026-03-04

🕵️Threat Intelligence

1
Wiz
CVE-2026-27446 Impact, Exploitability, and Mitigation Steps | Wiz

💬Community

1
Bugzilla
CVE-2026-27446 org.apache.artemis:artemis-server: org.apache.activemq:artemis-server: Apache Artemis, Apache ActiveMQ Artemis: Message injection and exfiltration due to missing authentication2026-03-04
CVE-2026-27446 — CRITICAL severity | cvebase