Red Hat EAP Artemis deserialization allows all classes by default
CVE-2026-86404 Published on September 7, 2026

Artemis-server: artemis-jms-client: artemis-core-client: undertow-core: wildfly-messaging-activemq-subsystem: artemis messaging handlers in red hat eap permit deserialization by default
EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list/block-list filtering via its checkSecurity()/isTrustedType() method. However, by default both allow-list and block-list are empty. When the allow-list is empty (size == 0), isTrustedType() returns true for ALL classes. This means all classes are deserializable by default.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-86404 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH

Timeline

Reported to Red Hat.

Made public. 88 days later.

Weakness Type

What is a Marshaling, Unmarshaling Vulnerability?

The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

CVE-2026-86404 has been classified to as a Marshaling, Unmarshaling vulnerability or weakness.


Products Associated with CVE-2026-86404

Want to know whenever a new CVE is published for Red Hat products? stack.watch will email you.

 
 
 
 
 

Affected Versions

Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7: Red Hat AMQ Broker 7: Red Hat build of Apache Camel 4 for Quarkus 3: Red Hat build of Apache Camel for Spring Boot 4: Red Hat build of Apache Camel for Spring Boot 4: Red Hat build of Apache Camel for Spring Boot 4: Red Hat JBoss Enterprise Application Platform 7: Red Hat JBoss Enterprise Application Platform 7: Red Hat JBoss Enterprise Application Platform 7: Red Hat JBoss Enterprise Application Platform 7: Red Hat JBoss Enterprise Application Platform 7: Red Hat JBoss Enterprise Application Platform 8: Red Hat JBoss Enterprise Application Platform 8: Red Hat JBoss Enterprise Application Platform 8: Red Hat JBoss Enterprise Application Platform 8: Red Hat JBoss Enterprise Application Platform 8: