CVE-2026-27446
CVSS 9.8 CRITICAL: missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. EPSS 1% (65º percentile).
Vulnerabilità · 140 giorni fa
Il rischio non è un crash del broker. Un attacker non autenticato sulla rete adiacente può costringere il broker ActiveMQ Artemis di Opcenter RDnL a federarsi con un rogue broker, quindi usare quel percorso per iniettare o deviare i messaggi che alimentano i workflow di produzione.
CVSS 9.8 CRITICAL: missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. EPSS 1% (65º percentile).
1 fonte che coprono questa storia
Siemens Opcenter RDnL Summary Opcenter RDnL is affected by missing authentication in critical function in ‘ActiveMQ Artemis’.
Part of the PlainSec briefing for 2026-05-14