CVE-2026-101292

high

Description

Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStreamConnectMessage.getFederationPolicy(). The method calls Class.forName(clazz).getConstructor().newInstance() where clazz is read directly from the CORE protocol wire buffer without type validation. An authenticated federation peer can send a FEDERATION_DOWNSTREAM_CONNECT packet with a crafted class name, causing the broker to load and instantiate arbitrary classes visible to the Artemis module classloader. Static initializers (<clinit>) and no-argument constructors (<init>()) execute as side effects before the type cast, enabling denial of service via system-property poisoning, out-of-memory conditions via classloading, or broker state manipulation.

References

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88242

https://bugzilla.redhat.com/show_bug.cgi?id=2482963

https://access.redhat.com/security/cve/CVE-2026-101292

https://access.redhat.com/errata/RHSA-2026:53806

https://access.redhat.com/errata/RHSA-2026:53644

Details

Source: Mitre, NVD

Published: 2026-09-28

Updated: 2026-09-29

Risk Information

CVSS v2

Base Score: 8.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:C

Severity: High

CVSS v3

Base Score: 8.2

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Severity: High

EPSS

EPSS: 0.00414