CVE-2026-49363
published 2026-09-10CVE-2026-49363: An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node details by sending a SUBSCRIBE_TOPOLOGY request prior to…
PriorityP351high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.29%
21.0th percentile
An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node details by sending a SUBSCRIBE_TOPOLOGY request prior to authentication.
This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0.
Users are recommended to upgrade to version 2.57.0, which fixes the issue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache_software_foundation | apache_activemq_artemis | 1.0.0 – 2.44.0 | — |
| apache_software_foundation | apache_artemis | 2.50.0 – 2.56.0 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
artemis-server: artemis-server: Pre-auth topology disclosure via CORE SUBSCRIBE_TOPOLOGY_V2 on channel0
vendor_redhat·2026-09-10·CVSS 9.8
CVE-2026-49363 [CRITICAL] CWE-306 artemis-server: artemis-server: Pre-auth topology disclosure via CORE SUBSCRIBE_TOPOLOGY_V2 on channel0
artemis-server: artemis-server: Pre-auth topology disclosure via CORE SUBSCRIBE_TOPOLOGY_V2 on channel0
A missing authentication vulnerability was found in Apache ActiveMQ Artemis. The SUBSCRIBE_TOPOLOGY_V2 handler in CoreProtocolManager.LocalChannelHandler.handlePacket() processes topology subscription requests on channel0 with zero authentication -- no call to getSecurityStore(), no credential verification, no subject validation. An unauthenticated attacker can send a single 5-byte packet on the CORE protocol (via :8080 HTTP-upgrade in EAP or :61616 in AMQ Broker) to obtain the broker's nodeID (type-1 UUID embedding MAC address), internal hostname/IP, port numbers, connector configurations, and backup/scale-down group names. In clustered deployments, a persistent ClusterTopologyListener
VulDB
Apache ActiveMQ Artemis Core Protocol information disclosure
vuldb·2026-09-10
CVE-2026-49363 [LOW] Apache ActiveMQ Artemis Core Protocol information disclosure
A vulnerability, which was classified as problematic, was found in Apache ActiveMQ Artemis. The impacted element is an unknown function of the component Core Protocol. Executing a manipulation can lead to information disclosure.
The identification of this vulnerability is CVE-2026-49363. The attack may be launched remotely. There is no exploit available.
No detection rules found.
No public exploits indexed.
2026-09-10
Published