Flaw in ActiveMQ Artemis OpenWire support
Summary
| CVE | CVE-2021-26118 |
|---|---|
| State | PUBLISHED |
| Assigner | apache |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-01-27 19:15:13 UTC |
| Updated | 2026-06-15 13:03:40 UTC |
| Description | While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 bypassed policy based access control for the entire session. Production of advisory messages was not subject to access control in error. |
Risk And Classification
Primary CVSS: v3.1 7.5 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS: 0.040080000 probability, percentile 0.892250000 (date 2026-06-21)
Problem Types: CWE-284 | NVD-CWE-Other | CWE-284 CWE-284 Improper Access Control
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
| 2.0 | [email protected] | Primary | 5 | AV:N/AC:L/Au:N/C:N/I:P/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
HighAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Artemis | 2.15.0 | All | All | All |
| Application | Netapp | Oncommand Workflow Automation | - | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Apache Software Foundation | Apache ActiveMQ Artemis | affected unspecified 2.16.0 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2021-26118 Apache ActiveMQ Artemis Vulnerability in NetApp Products | NetApp Product Security | af854a3a-2127-422b-91ae-364da2661108 | security.netapp.com | Third Party Advisory |
| lists.apache.org/thread.html/rafd5d7cf303772a0118865262946586921a65ebd98fc24f5... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| CVE-2021-26118: Flaw in ActiveMQ Artemis OpenWire support | af854a3a-2127-422b-91ae-364da2661108 | mail-archives.apache.org | Mailing List, Vendor Advisory |
| Pony Mail! | MITRE | lists.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Apache ActiveMQ would like to thank Francesco Marchioni (Red Hat) for reporting this issue. (en)
Additional Advisory Data
Workarounds
CNA: Upgrade to Apache ActiveMQ Artemis 2.16.0
Legacy QID Mappings
- 981417 Java (maven) Security Update for org.apache.activemq:apache-artemis (GHSA-q7fr-vqhq-v5xr)