CVE-2026-4649
mediumCVSS v3 Base Score
6.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
EPSS Score
0.0%
Exploitation probability in 30 days
Top 86% most likely to be exploited
Attack Characteristics
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Confidentiality
High
Integrity
Low
Availability
None
Published: March 24, 2026 (51 days ago)
Last Modified: March 24, 2026
Vendor: Red Hat
Source: REDHAT
Vulnerability Report
Generated by CyberWatcher
Description
A flaw was found in Apache Artemis and KNIME Business Hub. A user with normal privileges and the ability to execute workflows in an executor can exploit an authentication bypass vulnerability. This allows the user to install and register a federated mirror without authentication to the original Apache Artemis instance. Consequently, the attacker can read all internal messages and inject new messages, leading to information disclosure and potential data integrity issues.
CWE
CWE-306Affected Products
Red Hat AMQ Broker 7Red Hat AMQ ClientsRed Hat build of Apache Camel for Spring Boot 4Red Hat build of OptaPlanner 8Red Hat Fuse 7Red Hat JBoss Enterprise Application Platform 7Red Hat JBoss Enterprise Application Platform 8Red Hat JBoss Enterprise Application Platform Expansion PackRed Hat Process Automation 7Red Hat Satellite 6