CVE-2026-57967
published 2026-09-10CVE-2026-57967: An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing execution of the…
PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.28%
20.2th percentile
An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing execution of the previously authenticated session.
This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0.
Users are recommended to upgrade to version 2.57.0, which fixes the issue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache_software_foundation | apache_activemq_artemis | 1.0.0 – 2.44.0 | — |
| apache_software_foundation | apache_artemis | 2.50.0 – 2.56.0 | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
artemis-server: Apache Artemis — session hijack via missing authentication
vendor_redhat·2026-09-10·CVSS 9.8
CVE-2026-57967 [CRITICAL] CWE-306 artemis-server: Apache Artemis — session hijack via missing authentication
artemis-server: Apache Artemis — session hijack via missing authentication
in Apache Artemis, the REATTACH_SESSION handler performs zero authentication — it looks up the session by name only and calls transferConnection() unconditionally, migrating the authenticated session to the attacker's connection. The hijacked cluster-bridge session inherits full broker-management authority (message injection, topology manipulation, journal access)
Package: artemis-server (Red Hat JBoss Enterprise Application Platform 7) - Affected
Package: artemis-server (Red Hat JBoss Enterprise Application Platform 8) - Affected
Package: artemis-server (Red Hat JBoss Enterprise Application Platform Expansion Pack) - Affected
VulDB
Apache ActiveMQ Artemis missing authentication
vuldb·2026-09-10
CVE-2026-57967 Apache ActiveMQ Artemis missing authentication
A vulnerability was found in Apache ActiveMQ Artemis. It has been rated as very critical. Affected by this issue is some unknown functionality. Performing a manipulation results in missing authentication.
This vulnerability is cataloged as CVE-2026-57967. It is possible to initiate the attack remotely. There is no exploit available.
No detection rules found.
No public exploits indexed.
2026-09-10
Published