CVE-2026-49362
published 2026-09-10CVE-2026-49362: An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker state manipulation and potential…
PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.23%
13.3th percentile
An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker state manipulation and potential denial of service.
This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0.
Users are recommended to upgrade to version 2.57.0, which fixes the issue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache_software_foundation | apache_activemq_artemis | 1.0.0 – 2.44.0 | — |
| apache_software_foundation | apache_artemis | 2.50.0 – 2.56.0 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apache ActiveMQ Artemis CORE Protocol missing authentication
vuldb·2026-09-10
CVE-2026-49362 [CRITICAL] Apache ActiveMQ Artemis CORE Protocol missing authentication
A vulnerability was found in Apache ActiveMQ Artemis. It has been classified as critical. Affected is an unknown function of the component CORE Protocol Handler. This manipulation causes missing authentication.
This vulnerability is tracked as CVE-2026-49362. The attack is possible to be carried out remotely. No exploit exists.
Red Hat
artemis-server: undertow-core: wildfly-messaging-activemq-subsystem: artemis core protocol permits unauthed queue creation
vendor_redhat·2026-09-10·CVSS 7.5
CVE-2026-49362 [HIGH] artemis-server: undertow-core: wildfly-messaging-activemq-subsystem: artemis core protocol permits unauthed queue creation
artemis-server: undertow-core: wildfly-messaging-activemq-subsystem: artemis core protocol permits unauthed queue creation
Artemis CORE protocol channel allows unauthed queue creation. an unauthenticated attacker can send CREATE_QUEUE packets on channel 1 via the :8080 HTTP-upgrade path to create arbitrary durable JMS queues on the embedded broker. This can be used for resource exhaustion and persistent broker-state manipulation.
Package: artemis-server (Red Hat AMQ Clients) - Affected
Package: artemis-core-client (Red Hat build of Apache Camel for Spring Boot 4) - Not affected
Package: artemis-server (Red Hat build of Apache Camel for Spring Boot 4) - Not affected
Package: artemis-server (Red Hat JBoss Enterprise Application Platform 7) - Affected
Package: undertow-core (Red Hat JBo
No detection rules found.
No public exploits indexed.
2026-09-10
Published