OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-101292

HIGH · CVSS 8.2 EPSS 0.43%

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

Apache ActiveMQ Artemis versions prior to 2.34.0 are vulnerable to an unsafe reflection issue that allows an authenticated federation peer to exploit the FederationStreamConnectMessage.getFederationPolicy() method. This vulnerability can lead to the instantiation of arbitrary classes, potentially resulting in denial of service, out-of-memory errors, or manipulation of the broker's state due to the execution of static initializers and constructors. Organizations using affected versions should prioritize patching to mitigate these risks.

CVE
CVE-2026-101292
Severity
HIGH
CVSS
8.2
EPSS
0.43%
Apache

Original NVD Description

Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStreamConnectMessage.getFederationPolicy(). The method calls Class.forName(clazz).getConstructor().newInstance() where clazz is read directly from the CORE protocol wire buffer without type validation. An authenticated federation peer can send a FEDERATION_DOWNSTREAM_CONNECT packet with a crafted class name, causing the broker to load and instantiate arbitrary classes visible to the Artemis module classloader. Static initializers (<clinit>) and no-argument constructors (<init>()) execute as side effects before the type cast, enabling denial of service via system-property poisoning, out-of-memory conditions via classloading, or broker state manipulation.