Sceawere

Vulnerability Detail

CVE-2026-101292UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

ActiveMQ Artemis Unsafe Reflection Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.2
Creation Date
3h ago
Vendor
Red Hat
Product
Red Hat AMQ Broker 7
Attack Type
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Attack Complexity
LOW

Narrative and Response

Description

Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStreamConnectMessage.getFederationPolicy(). The method calls Class.forName(clazz).getConstructor().newInstance() where clazz is read directly from the CORE protocol wire buffer without type validation. An authenticated federation peer can send a FEDERATION_DOWNSTREAM_CONNECT packet with a crafted class name, causing the broker to load and instantiate arbitrary classes visible to the Artemis module classloader. Static initializers (<clinit>) and no-argument constructors (<init>()) execute as side effects before the type cast, enabling denial of service via system-property poisoning, out-of-memory conditions via classloading, or broker state manipulation.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.2",
  "pubDate": "2026-09-28T13:17:21.267Z",
  "pubdate": "2026-09-28T13:17:21.267Z",
  "executiveSummary": "Apache ActiveMQ Artemis versions prior to 2.34.0 are susceptible to an unsafe reflection vulnerability residing in the FederationStreamConnectMessage component.\nThe vulnerability arises from the insecure deserialization and instantiation of arbitrary classes via the CORE protocol.\nAn authenticated federation peer can exploit this flaw by supplying a malicious class name within a FEDERATION_DOWNSTREAM_CONNECT packet, bypassing type validation.\nSuccessful exploitation allows for the execution of arbitrary class static initializers and constructors, which may lead to Denial of Service (DoS) through resource exhaustion, system property manipulation, or broker state compromise.\nThis vulnerability is critical due to the potential for remote code execution or system instability within the broker environment.\nThe impact is significant as it affects the core messaging infrastructure, requiring immediate remediation to prevent unauthorized manipulation of the Artemis module classloader.",
  "technicalDetails": "The vulnerability is rooted in the FederationStreamConnectMessage.getFederationPolicy() method, which performs unsafe reflection. The method retrieves a class name string (clazz) directly from the CORE protocol wire buffer without performing any form of allow-listing or type validation. This string is subsequently passed to Class.forName(clazz).getConstructor().newInstance().\nIn the context of the Apache ActiveMQ Artemis architecture, the CORE protocol allows for binary communication between brokers. By crafting a FEDERATION_DOWNSTREAM_CONNECT packet, an authenticated attacker can force the broker's JVM to load and instantiate any class accessible within the Artemis module classloader scope. Because the instantiation occurs before the subsequent type cast check, the broker is forced to execute the target class's static initializer (<clinit>) and its no-argument constructor (<init>()) as an immediate side effect of the reflection operation.\nThe attack flow proceeds as follows: First, the attacker establishes a connection as a federation peer, which is a prerequisite for sending federation-related packets. Second, the attacker crafts a malicious FEDERATION_DOWNSTREAM_CONNECT packet containing an arbitrary class name. Third, the Apache ActiveMQ Artemis server processes this packet through the vulnerable FederationStreamConnectMessage logic. Fourth, the server invokes Class.forName() on the attacker-supplied string. Fifth, the classloader identifies the class, triggering its static initialization blocks. Sixth, the server invokes the class's no-argument constructor.\nThe implications of this execution are severe. By instantiating arbitrary classes, an attacker can manipulate system properties to alter the broker's security posture or operational environment. Furthermore, the arbitrary loading of classes can lead to out-of-memory conditions or complex Denial of Service states that are difficult to recover from without a full service restart. This vector effectively bypasses standard object-oriented security controls within the messaging middleware, transforming a legitimate administrative packet structure into a vehicle for arbitrary code execution during the instantiation phase. The reliance on the classloader scope suggests that any class available on the classpath—including those used by the broker for internal logic or those included in the provided application dependencies—is a potential target for manipulation."
}
CVE-2026-101292: ActiveMQ Artemis Unsafe Reflection Vulnerability (HIGH Severity, CVSS: 8.2) | Sceawere