CVE Explorer
CVE-2026-4649
Apache Artemis before version 2.52.0 is affected by an authentication bypass flaw which allows reading all messages exchanged via the broker and injection of new message ( CVE-2026-27446 https://www.cve.org/CVERecord ). Since KNIME Business Hub uses Apache Artemis it is also affected by the issue. However, since Apache Artemis is not exposed to the outside it requires at least normal user privileges and the ability to execute workflows in an executor. Such a user can install and register a feder
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"KNIME Business Hub","vendor":"KNIME","versions":[{"lessThan":"1.17.4","status":"affected","version":"1.17.0","versionType":"semver"},{"lessThan":"1.16.3","status":"affected","version":"1.16.0","versionType":"semver"},{"lessThan":"1.15.2","status":"affected","version":"0.0.0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:dad0daeec1026784468bb85f965069f601be21640d6297306722afba9bf2e4a7 · sha256:a9b01d787ef16af9… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"YES","Recovery":"USER","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":5.3,"baseSeverity":"MEDIUM","exploitMaturity":"NOT_DEFINED","privilegesRequired":"LOW","providerUrgency":"AMBER","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"CONCENTRATED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/AU:Y/R:U/V:C/RE:M/U:Amber","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImp…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:dad0daeec1026784468bb85f965069f601be21640d6297306722afba9bf2e4a7 · sha256:a9b01d787ef16af9… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-306","description":"CWE-306 Missing authentication for critical function","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:dad0daeec1026784468bb85f965069f601be21640d6297306722afba9bf2e4a7 · sha256:a9b01d787ef16af9… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://www.knime.com/security/advisories#CVE-2026-4649"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:dad0daeec1026784468bb85f965069f601be21640d6297306722afba9bf2e4a7 · sha256:a9b01d787ef16af9… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.