PT-2026-86687 · Red Hat · Red Hat Amq Broker 7+5
CVE-2026-86404
·
Publicado
2026-09-07
·
Atualizado
2026-09-12
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
🚨HIGH - Red Hat EAP Artemis ObjectMessage Unsafe Deserialization Default (CVE-2026-86404)
In Red Hat EAP’s Artemis messaging, the deserialization trust check allows any class when both allow-list and block-list are empty, so untrusted ObjectMessage payloads deserialize by default. Remote attackers can trigger gadget chains leading to RCE unless a restrictive allow-list is configured.
👉Affected: Red Hat EAP Artemis (artemis-server, artemis-core-client, artemis-jms-client, undertow-core, wildfly-messaging-activemq-subsystem)
Correção
RCE
Deserialization of Untrusted Data
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Red Hat Amq Broker 7
Red Hat Jboss Enterprise Application Platform 7
Red Hat Jboss Enterprise Application Platform 7.4 Els On Rhel 7
Red Hat Enterprise Application Platform 8
Red Hat Build Of Apache Camel 4 For Quarkus 3
Red Hat Build Of Apache Camel For Spring Boot 4