CVE-2026-101292
Received Received - Intake

Unsafe Reflection in Apache ActiveMQ Artemis

Vulnerability report for CVE-2026-101292, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: redhat-SADP

Description

Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStreamConnectMessage.getFederationPolicy(). The method calls Class.forName(clazz).getConstructor().newInstance() where clazz is read directly from the CORE protocol wire buffer without type validation. An authenticated federation peer can send a FEDERATION_DOWNSTREAM_CONNECT packet with a crafted class name, causing the broker to load and instantiate arbitrary classes visible to the Artemis module classloader. Static initializers (<clinit>) and no-argument constructors (<init>()) execute as side effects before the type cast, enabling denial of service via system-property poisoning, out-of-memory conditions via classloading, or broker state manipulation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
redhat jboss_enterprise_application_platform 7.4.25
bouncy_castle bcprov_jdk18on *
bouncy_castle bcprov_jdk15on *
bouncy_castle bcprov_jdk15 *
bouncy_castle bcprov_jdk12 *
apache activemq_artemis to 2.34.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-470 The product uses external input with reflection to select which classes or code to use, but it does not sufficiently prevent the input from selecting improper classes or code.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Apache ActiveMQ Artemis before 2.34.0 has an unsafe reflection vulnerability in the FederationStreamConnectMessage.getFederationPolicy() method. It uses Class.forName(clazz).getConstructor().newInstance() without validating the class name from the CORE protocol buffer. An authenticated attacker can send a crafted packet to load and instantiate arbitrary classes, leading to system-property poisoning, out-of-memory conditions, or broker state manipulation.

Detection Guidance

Detecting this vulnerability requires checking Apache ActiveMQ Artemis versions and monitoring for suspicious network traffic. Use commands like 'rpm -qa | grep activemq-artemis' or 'dpkg -l | grep activemq-artemis' to check installed versions. Ensure versions are 2.34.0 or higher. Monitor logs for unexpected FEDERATION_DOWNSTREAM_CONNECT packets or classloading errors.

For Red Hat systems, verify if the errata RHSA-2026:53644 is applied using 'yum list-security --cve CVE-2026-101292' or 'dnf list-security --cve CVE-2026-101292'.

Impact Analysis

This vulnerability allows an attacker to execute arbitrary code, cause denial of service via out-of-memory errors, or manipulate broker state. It can lead to system crashes, unauthorized access, or data leaks depending on the classes loaded.

Mitigation Strategies

Immediately upgrade Apache ActiveMQ Artemis to version 2.34.0 or higher to address the primary fix. For Red Hat JBoss EAP 7.4 systems, apply RHSA-2026:53644 to update to eap7-activemq-artemis 2.16.0-22.redhat_00057 or later.

If upgrading is not immediately possible, restrict network access to the Artemis broker, especially federation ports, and monitor for unauthorized connections or classloading activities.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101292. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart