Impact
CVE-2026-27446 is a critical missing-authentication issue in Apache ActiveMQ Artemis outbound Core federation handling [S1][S2]. If an affected broker accepts Core protocol traffic from untrusted clients and can initiate outbound Core connections to untrusted targets, the broker trust boundary can be crossed without the authentication the operator expects.
Treat affected broker runtimes as urgent patch candidates, especially when Artemis is reachable from untrusted networks, shared internal networks, CI environments, or tenant-controlled infrastructure.
Root Cause
The advisory class is CWE-306: missing authentication for a security-sensitive broker control path [S2][S3]. Advisory sources describe affected releases where unauthenticated Core protocol behavior can influence outbound federation setup. Runtime impact still depends on the deployed broker version, acceptor/protocol configuration, and network egress policy.
Affected Versions
Advisory sources identify two Maven coordinates and version ranges [S2]:
org.apache.activemq:artemis-serverversions2.11.0through2.44.0.org.apache.artemis:artemis-serverversions2.50.0through2.51.x.
Upgrade Apache Artemis server runtimes to 2.52.0 or later where that coordinate is used, or use a vendor-supported unaffected build or backport [S1][S2].
Fix
Upgrade the broker runtime that actually serves traffic, not only the source manifest. Regenerate Maven or Gradle metadata, rebuild broker images and deployment artifacts, and confirm the running broker version after rollout.
While upgrading, review whether Core protocol acceptors are reachable from untrusted networks, require mutual TLS or documented broker-side authentication controls for broker control-plane traffic, and restrict outbound broker egress to trusted federation peers.
Covered by FixVibe
FixVibe's GitHub repo scans flag Maven and Gradle build files that pin or allow the affected artemis-server ranges, with remediation guidance.
