Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-49364: Apache Artemis clusters may reveal admin passwords to nearby attackers
CVE-2026-49364 · published 15 days ago
Summary
If a malicious computer is on the same network, it can watch the initial handshake when Artemis nodes join a cluster and capture the administrative credentials. This could allow an unauthenticated attacker to gain full control of the messaging system. Upgrade the Artemis software to the latest release (2.57.0 or later) to close the exposure.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| apache software foundation | apache artemis | <= 2.56.0 |
| apache software foundation | apache activemq artemis | <= 2.44.0 |
| apache | artemis |
>= 1.0.0, < 2.44.0 >= 2.50.0, < 2.57.0 cpe:2.3:a:apache:artemis:*:*:*:*:*:*:*:* |
Original advisory text
Apache Artemis, Apache Artemis, Apache ActiveMQ Artemis, Apache ActiveMQ Artemis: Pre-Authentication Cluster Credential Exposure to Discovered Peers
An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake.
This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0.
Users are recommended to upgrade to version 2.57.0, which fixes the issue.
This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0.
Users are recommended to upgrade to version 2.57.0, which fixes the issue.
References
- http://www.openwall.com/lists/oss-security/2026/09/10/3 URL
- https://repo.maven.apache.org/maven2 URL
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/49xxx/CVE-2026-49364... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-49364 Vendor Advisory
- https://lists.apache.org/thread/4qbgcz3k38q30bfbf7hphtomrdc8l8n8 Vendor Advisory
Severity
9.1
Critical
Exploitation
EPSS <1%
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published10 Sep 2026
Updated25 Sep 2026
First seen10 Sep 2026
Track software like this
Free during beta