CVE-2026-49362

Summary

An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker state manipulation and potential denial of service.

This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0.

Users are recommended to upgrade to version 2.57.0, which fixes the issue.

Affected Software

VendorProductVersion RangeStatus
Apache Software FoundationApache Artemis2.50.0 <= 2.56.0affected
Apache Software FoundationApache ActiveMQ Artemis1.0.0 <= 2.44.0affected

Weaknesses

  • CWE-306: CWE-306 Missing authentication for critical function

ADP Enrichment

CVE Program Container

Additional References

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References