Critical flaw lets unauthenticated attackers redirect Apache Artemis brokers

Apache has disclosed a critical vulnerability, CVE-2026-27446, in Apache Artemis and Apache ActiveMQ Artemis. Missing authentication checks in the Core federation functionality allow an unauthenticated remote attacker to force a broker to open a connection to a server the attacker controls. That hostile broker can then inject messages into queues or retrieve messages from them. Affected versions are Artemis 2.50.0 through 2.51.0 and ActiveMQ Artemis 2.11.0 through 2.44.0, with the fix in version 2.52.0.

What this means for your organisation

Message brokers rarely reach the boardroom, but they are often the nervous system connecting business applications, payment flows and supplier integrations. If someone can read the messages, business data leaks. If someone can inject messages, they can in practice trigger downstream transactions or changes without ever logging in. The exposure is greatest where the broker accepts Core connections from networks you do not control while also being allowed to connect outbound to external systems.

Berigo recommends

  • Map where you run Artemis or ActiveMQ Artemis, including at suppliers and inside purchased solutions, and upgrade to 2.52.0.
  • Where upgrading has to wait, block Core protocol access from untrusted networks and require mutual TLS with certificates.
  • Restrict which outbound connections the broker is permitted to make rather than letting it reach anything.
  • Add messaging infrastructure to your inventory of critical components so it is picked up the next time an urgent advisory lands.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch