Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-44417

Опубликовано: 22 мая 2026
Источник: redhat
CVSS3: 7.5

Описание

The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.

A flaw was found in Apache CXF. Untrusted users, if allowed to configure Java Message Service (JMS) for Apache CXF, can exploit this vulnerability to achieve remote code execution (RCE). This issue arises from an incomplete fix for a prior security flaw, indicating an alternative path that could lead to code execution.

Отчет

This is an Important flaw in Apache CXF where an incomplete fix for a prior vulnerability allows remote code execution. Exploitation requires that untrusted users have permissions to configure Java Message Service (JMS) within the Apache CXF environment, which is not a default configuration in Red Hat products. Successful exploitation could lead to arbitrary code execution with the privileges of the affected service.

Меры по смягчению последствий

To mitigate this issue, ensure that only trusted users have permissions to configure Java Message Service (JMS) for Apache CXF. Restrict access to configuration files and management interfaces that control JMS settings. If JMS functionality is not required, consider disabling it to remove the attack vector.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7cxf-rt-transports-jmsOut of support scope
Red Hat JBoss Enterprise Application Platform 7cxf-rt-transports-jmsOut of support scope
Red Hat JBoss Enterprise Application Platform 8cxf-rt-transports-jmsAffected
Red Hat JBoss Enterprise Application Platform Expansion Packcxf-rt-transports-jmsNot affected
Red Hat Single Sign-On 7cxf-rt-transports-jmsOut of support scope
Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16cxf-rt-transports-jmsFixedRHSA-2026:3739009.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-15
https://bugzilla.redhat.com/show_bug.cgi?id=2480729org.apache.cxf/cxf-rt-transports-jms: Apache CXF: Remote Code Execution via untrusted JMS configuration

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
2 месяца назад

The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.

CVSS3: 7.5
github
2 месяца назад

Apache CXF: Untrusted JMS configuration can lead to RCE

7.5 High

CVSS3