PT-2026-86687 · Red Hat · Red Hat Amq Broker 7+5

CVE-2026-86404

·

Publicado

2026-09-07

·

Atualizado

2026-09-12

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
🚨HIGH - Red Hat EAP Artemis ObjectMessage Unsafe Deserialization Default (CVE-2026-86404)
In Red Hat EAP’s Artemis messaging, the deserialization trust check allows any class when both allow-list and block-list are empty, so untrusted ObjectMessage payloads deserialize by default. Remote attackers can trigger gadget chains leading to RCE unless a restrictive allow-list is configured.
👉Affected: Red Hat EAP Artemis (artemis-server, artemis-core-client, artemis-jms-client, undertow-core, wildfly-messaging-activemq-subsystem)

Correção

RCE

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-86404

Produtos afetados

Red Hat Amq Broker 7
Red Hat Jboss Enterprise Application Platform 7
Red Hat Jboss Enterprise Application Platform 7.4 Els On Rhel 7
Red Hat Enterprise Application Platform 8
Red Hat Build Of Apache Camel 4 For Quarkus 3
Red Hat Build Of Apache Camel For Spring Boot 4