Red Hat Product Errata RHSA-2026:67603 - Security Advisory Issued: 2026-09-15 Updated: 2026-09-15 RHSA-2026:67603 - Security Advisory Overview Synopsis Important: Red Hat JBoss Enterprise Application Platform 7.4.25 security update Type/Severity Security Advisory: Important Topic A security update is now available for Red Hat JBoss Enterprise Application Platform 7.4. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on the WildFly application runtime. This asynchronous patch is a security update for Red Hat JBoss Enterprise Application Platform 7.4. Security Fix(es): artemis-server: Apache Artemis — session hijack via missing authentication (CVE-2026-57967) artemis-server: artemis core protocol permits unauthed queue creation (CVE-2026-49362) jackson-databind: Jackson-databind: Privilege escalation via improper handling of @JsonUnwrapped properties (CVE-2026-59889) jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified (CVE-2026-54515) For more details about the security issue(s), including the impact, a CVSS score, acknowledgements, and other related information, refer to the CVE page(s) listed in the References section. Solution Before applying the update, make sure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Affected Products JBoss Enterprise Application Platform 7.4 ELS 7 x86_64 Fixes BZ - 2477945 - CVE-2026-49362 artemis-server: undertow-core: wildfly-messaging-activemq-subsystem: artemis core protocol permits unauthed queue creation BZ - 2480638 - CVE-2026-57967 artemis-server: Apache Artemis ? session hijack via missing authentication BZ - 2492016 - CVE-2026-54515 jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified BZ - 2500653 - CVE-2026-59889 com.fasterxml.jackson.core/jackson-databind: Jackson-databind: Privilege escalation via improper handling of @JsonUnwrapped properties CVEs CVE-2026-49362 CVE-2026-49364 CVE-2026-54515 CVE-2026-57967 CVE-2026-59889 References https://access.redhat.com/security/updates/classification/#important https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.4 https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.4/html-single/installation_guide/index The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .
This security update for Red Hat JBoss Enterprise Application Platform 7.4 addresses multiple vulnerabilities, including a critical (CVSS 9.8) session hijack flaw in Apache Artemis due to missing authentication and a high-severity (CVSS 7.5) issue allowing unauthenticated queue creation. The update also fixes two medium-severity (CVSS 6.5) privilege escalation and property modification vulnerabilities in the Jackson-databind library. The patch is contained in version 7.4.25, which administrators should apply after backing up their installations.