PT-2026-86687 · Red Hat · Red Hat Amq Broker 7+5
CVE-2026-86404
·
Published
2026-09-07
·
Updated
2026-09-12
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
🚨HIGH - Red Hat EAP Artemis ObjectMessage Unsafe Deserialization Default (CVE-2026-86404)
In Red Hat EAP’s Artemis messaging, the deserialization trust check allows any class when both allow-list and block-list are empty, so untrusted ObjectMessage payloads deserialize by default. Remote attackers can trigger gadget chains leading to RCE unless a restrictive allow-list is configured.
👉Affected: Red Hat EAP Artemis (artemis-server, artemis-core-client, artemis-jms-client, undertow-core, wildfly-messaging-activemq-subsystem)
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat Amq Broker 7
Red Hat Jboss Enterprise Application Platform 7
Red Hat Jboss Enterprise Application Platform 7.4 Els On Rhel 7
Red Hat Enterprise Application Platform 8
Red Hat Build Of Apache Camel 4 For Quarkus 3
Red Hat Build Of Apache Camel For Spring Boot 4