CVE-2026-57967

high Red Hat
CVSS v3 Base Score
7.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Characteristics
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Confidentiality
High
Integrity
High
Availability
None
Published: September 10, 2026 (1 days ago)
Last Modified: September 10, 2026
Vendor: Red Hat
Source: REDHAT

Description

in Apache Artemis, the REATTACH_SESSION handler performs zero authentication — it looks up the session by name only and calls transferConnection() unconditionally, migrating the authenticated session to the attacker's connection. The hijacked cluster-bridge session inherits full broker-management authority (message injection, topology manipulation, journal access)

CWE

CWE-306

Affected Products

Red Hat AMQ Broker 7Red Hat JBoss Enterprise Application Platform 7Red Hat JBoss Enterprise Application Platform 8Red Hat JBoss Enterprise Application Platform Expansion Pack

References