Skip to main content
QUIETLYTIC
Vulnerability

Red Hat JBoss EAP Insecure Deserialization (CVE-2026-86404)

CVE-2026-86404 is a CVSS 8.8 high-severity insecure-deserialization flaw in JBoss EAP embedded ActiveMQ Artemis, where empty allow/block lists mean every class is deserializable by default.

CVE-2026-86404
Threat Level
HIGH
CVSS
8.8
Status
Monitored
Confidence
Medium
Affected Products
Red Hat JBoss EAP (Apache ActiveMQ Artemis)

CVE-2026-86404 is a high-severity (CVSS 3.1 base 8.8) insecure-deserialization vulnerability affecting EAP’s embedded Artemis (Apache ActiveMQ Artemis) messaging component, per Red Hat’s own errata and bug tracker.

What the vulnerability does

Per NVD’s description, Artemis’s ObjectMessage.getObject() method deserializes objects via ObjectInputStreamWithClassLoader, which is designed to filter deserialization using an allow-list/block-list mechanism (checkSecurity()/isTrustedType()). The flaw: both lists are empty by default, and when the allow-list has zero entries, isTrustedType() returns true for every class it’s asked about — meaning the filter that’s supposed to restrict deserialization to known-safe types instead permits all of them.

The CVSS vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) reflects a network-reachable, low-complexity flaw requiring low privileges and no user interaction, with full confidentiality, integrity, and availability impact — consistent with insecure deserialization’s well-established path to remote code execution via a crafted serialized object.

What we don’t yet have

This record traces to Red Hat’s own errata (RHSA-2026:53644) and Bugzilla entry via NVD; no CISA KEV listing is present in our ingested data. Confidence is medium — check Red Hat’s errata directly for the specific EAP/AMQ Broker version range and remediation steps, since our ingested record doesn’t carry affected/fixed version data.

Why this matters

Insecure deserialization vulnerabilities are a well-established class with a direct path to remote code execution once an attacker can supply a crafted serialized payload to the vulnerable endpoint. A default configuration where the security filter is present in code but silently permits everything because its allow-list starts empty is a particularly dangerous failure mode: administrators who assume the filtering mechanism is protecting them, simply because it exists, are not actually protected until they explicitly populate an allow-list. Any JBoss EAP deployment using Artemis for messaging should apply Red Hat’s patch and confirm the allow-list is explicitly configured, not just present.

Frequently Asked Questions

What is CVE-2026-86404? A CVSS 8.8 high-severity insecure-deserialization vulnerability in JBoss EAP’s embedded Apache ActiveMQ Artemis component, where an empty default allow-list makes every class deserializable.

Where can I find the fix for CVE-2026-86404? Red Hat’s own errata, RHSA-2026:53644, referenced via NVD — consult it directly for affected versions and patched builds.

Is CVE-2026-86404 being actively exploited? No evidence of active exploitation has been reported as of this writing; it is not listed in CISA’s KEV catalog.


Data sourced from the National Vulnerability Database (NVD) and Red Hat’s security errata, aggregated September 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)

Related intelligence


Analyst tools