CVE-2026-27446 is a Critical Missing Authentication for Critical Function (CWE-306) vulnerability affecting Apache Artemis (versions 2.50.0-2.51.0) and Apache ActiveMQ Artemis (versions 2.11.0-2.44.0). An unauthenticated remote attacker can exploit this by forcing a target broker to establish an outbound Core federation connection to an attacker-controlled rogue broker. This can lead to message injection into and/or exfiltration from any queue, impacting environments allowing both untrusted incoming and outgoing Core protocol connections. With a CVSS score of 9.3 (CRITICAL), this vulnerability has a network attack vector and low attack complexity, requiring no privileges or user interaction. The potential impact is high for confidentiality and integrity, with a moderate impact on availability. The FAUCET Risk Score is 53/100, indicating significant risk. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. However, the vulnerability has garnered community attention with 3 mentions, including discussions on security mailing lists and Japanese media coverage, suggesting awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.11.0, <= 2.44.0CPE matchmatch criteria | cpe:2.3:a:apache:artemis:*:*:*:*:*:*:*:* | ||
2.50.0CPE matchmatch criteria | cpe:2.3:a:apache:artemis:2.50.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache Artemis and Apache ActiveMQ Artemis are Missing Authentication for Critical Functions
Mar 4, 2026CVE-2026-27446: Apache Artemis, Apache ActiveMQ Artemis: Auth bypass for Core downstream federation
Mar 3, 2026