EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list/block-list filtering via its checkSecurity()/isTrustedType() method. However, by default both allow-list and block-list are empty. When the allow-list is empty (size == 0), isTrustedType() returns true for ALL classes. This means all classes are deserializable by default.
History

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat build Of Apache Camel For Quarkus
Redhat build Of Apache Camel For Spring Boot
Vendors & Products Redhat build Of Apache Camel For Quarkus
Redhat build Of Apache Camel For Spring Boot

Mon, 07 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat jboss Enterprise Application Platform Els
CPEs cpe:/a:redhat:jboss_enterprise_application_platform_els:7.4::el7
Vendors & Products Redhat jboss Enterprise Application Platform Els
References

Mon, 07 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list/block-list filtering via its checkSecurity()/isTrustedType() method. However, by default both allow-list and block-list are empty. When the allow-list is empty (size == 0), isTrustedType() returns true for ALL classes. This means all classes are deserializable by default.
Title Artemis-server: artemis-jms-client: artemis-core-client: undertow-core: wildfly-messaging-activemq-subsystem: artemis messaging handlers in red hat eap permit deserialization by default
First Time appeared Redhat
Redhat amq Broker
Redhat camel Quarkus
Redhat camel Spring Boot
Redhat jboss Enterprise Application Platform
Weaknesses CWE-502
CPEs cpe:/a:redhat:amq_broker:7
cpe:/a:redhat:camel_quarkus:3
cpe:/a:redhat:camel_spring_boot:4
cpe:/a:redhat:jboss_enterprise_application_platform:7
cpe:/a:redhat:jboss_enterprise_application_platform:8
Vendors & Products Redhat
Redhat amq Broker
Redhat camel Quarkus
Redhat camel Spring Boot
Redhat jboss Enterprise Application Platform
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2026-09-07T11:35:04.324Z

Updated: 2026-09-09T14:23:36.668Z

Reserved: 2026-09-07T11:24:28.229Z

Link: CVE-2026-86404

cve-icon Vulnrichment

Updated: 2026-09-09T14:23:32.826Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-07T12:17:21.840

Modified: 2026-09-09T15:17:17.400

Link: CVE-2026-86404

cve-icon Redhat

No data.