PT-2026-86687 · Red Hat · Red Hat Amq Broker 7+5

CVE-2026-86404

·

Published

2026-09-07

·

Updated

2026-09-12

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
🚨HIGH - Red Hat EAP Artemis ObjectMessage Unsafe Deserialization Default (CVE-2026-86404)
In Red Hat EAP’s Artemis messaging, the deserialization trust check allows any class when both allow-list and block-list are empty, so untrusted ObjectMessage payloads deserialize by default. Remote attackers can trigger gadget chains leading to RCE unless a restrictive allow-list is configured.
👉Affected: Red Hat EAP Artemis (artemis-server, artemis-core-client, artemis-jms-client, undertow-core, wildfly-messaging-activemq-subsystem)

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86404

Affected Products

Red Hat Amq Broker 7
Red Hat Jboss Enterprise Application Platform 7
Red Hat Jboss Enterprise Application Platform 7.4 Els On Rhel 7
Red Hat Enterprise Application Platform 8
Red Hat Build Of Apache Camel 4 For Quarkus 3
Red Hat Build Of Apache Camel For Spring Boot 4