Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
internet-facing-service-vulnerabilitywidely-deployed-product-advisorydata-exfiltration-methodinitial-access-method

Authentication Bypass in Apache Artemis Core Downstream Federation (CVE-2026-27446)

Updated 3mo agoFirst seen Mar 5, 20262 sources

CVE-2026-27446 is a critical missing authentication for a critical function (CWE-306) in Apache Artemis and Apache ActiveMQ Artemis that enables an unauthenticated remote attacker to abuse the Core protocol to force a target broker to establish an outbound Core downstream federation connection to an attacker-controlled rogue broker. If successful, the attacker can inject arbitrary messages into any queue and/or exfiltrate messages from any queue via the rogue broker, particularly in environments that allow incoming Core protocol connections from untrusted sources and outgoing Core protocol connections to untrusted destinations.

Impacted versions include Apache Artemis 2.50.0–2.51.0 and Apache ActiveMQ Artemis 2.11.0–2.44.0; upgrading to Apache Artemis 2.52.0 is recommended to remediate. Mitigations include removing Core protocol support from untrusted-facing acceptors (notably the default artemis acceptor on port 61616 if configured to allow Core) or enforcing two-way TLS (mTLS) to require certificate-based client authentication before protocol negotiation. The Centre for Cybersecurity Belgium highlighted the high severity (reported as CVSS 9.3) and noted no vendor warning of active exploitation as of early March 2026, while emphasizing that ActiveMQ-family products have been repeatedly targeted historically for follow-on activity such as ransomware deployment.

Share:
Authentication Bypass in Apache Artemis Core Downstream Federation (CVE-2026-27446)
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Mar 5, 20264mo ago

Belgium CCB issues public warning to patch CVE-2026-27446

The Belgian Centre for Cybersecurity published an advisory warning that the authentication bypass vulnerability affecting Apache Artemis and Apache ActiveMQ Artemis could lead to message injection and exfiltration. The notice urged organizations to patch immediately.

Mar 4, 20264mo ago

Apache recommends upgrading to Artemis 2.52.0 and applying mitigations

Apache advised affected users to upgrade to Apache Artemis 2.52.0 to address the vulnerability. It also documented mitigations such as disabling the Core protocol on untrusted-facing acceptors or enforcing mutual TLS with client certificates before protocol handshake.

Apache discloses CVE-2026-27446 in Artemis and ActiveMQ Artemis

A missing-authentication flaw in the Core downstream federation feature was disclosed as CVE-2026-27446, allowing an unauthenticated remote attacker to coerce a broker into creating an outbound federation connection to a rogue broker. The issue can enable message injection or exfiltration from queues in affected deployments that accept untrusted incoming Core connections and allow untrusted outgoing Core connections.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

6 LINKEDOpen in app
Malware
1 linked
Organizations
4 linked
The DFIR ReportOffensive SecurityApache Software FoundationCentre for Cybersecurity Belgium
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.