Red Hat Security Advisory: Red Hat AMQ Broker 7.12.6 release and security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-27446 — org.apache.artemis:artemis-server: org.apache.activemq:artemis-server: Apache Artemis, Apache ActiveMQ Artemis: Message injection and exfiltration due to missing authentication
🎯 Affected products1
- Red Hat AMQ Broker 7.12.6
✅ Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings. The References section of this erratum contains a download link (you must log in to download the update). Workaround: To mitigate this issue, restrict Core protocol support on acceptors receiving connections from untrusted sources. The default "artemis" acceptor on port 61616 supports all protocols, including Core. Modify the acceptor URL to explicitly exclude the Core protocol using the "protocols" URL parameter. Alternatively, configure two-way SSL with certificate-based authentication to prevent unauthenticated exploitation. A service restart or reload may be required for changes to take effect.
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2026:3955
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/updates/classification#important
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=jboss.amq.broker&version=7.12.6
- externalhttps://docs.redhat.com/en/documentation/red_hat_amq_broker/7.12
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2444320
- externalhttps://issues.redhat.com/browse/ENTMQBR-10147
- externalhttps://issues.redhat.com/browse/ENTMQBR-10166
- externalhttps://issues.redhat.com/browse/ENTMQBR-10169
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_3955.json