Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-49364: Apache Artemis clusters may reveal admin passwords to nearby attackers

CVE-2026-49364 · published 15 days ago
Summary

If a malicious computer is on the same network, it can watch the initial handshake when Artemis nodes join a cluster and capture the administrative credentials. This could allow an unauthenticated attacker to gain full control of the messaging system. Upgrade the Artemis software to the latest release (2.57.0 or later) to close the exposure.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
apache software foundation apache artemis <= 2.56.0
apache software foundation apache activemq artemis <= 2.44.0
apache artemis >= 1.0.0, < 2.44.0
>= 2.50.0, < 2.57.0
cpe:2.3:a:apache:artemis:*:*:*:*:*:*:*:*
Original advisory text
Apache Artemis, Apache Artemis, Apache ActiveMQ Artemis, Apache ActiveMQ Artemis: Pre-Authentication Cluster Credential Exposure to Discovered Peers
An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake.

This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0.



Users are recommended to upgrade to version 2.57.0, which fixes the issue.
Severity
9.1 Critical
Exploitation
EPSS <1%
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published10 Sep 2026
Updated25 Sep 2026
First seen10 Sep 2026
Sources
CVE-2026-49364 · MITRE
Track software like this
Free during beta