Back to blog

// OSSeva Blog

Security

Apache ActiveMQ Artemis CVE-2026-57967: Fixed Only in 2.57.0

Matt Reynolds6 min read

The short answer

CVE-2026-57967 is a missing authentication check in the Artemis CORE protocol. An unauthenticated remote attacker can send a crafted SESSION_REATTACH packet, take over an existing session and carry on as the user who authenticated it. NVD published it on 10 September 2026 with a CVSS 3.1 score of 9.8 added by CISA-ADP; Apache's own rating is important. CISA's assessment on the NVD record, dated 10 September, lists no known exploitation, rates the flaw automatable and gives its technical impact as total.

The advisory lists every release as affected, Apache Artemis 2.50.0 to 2.56.0 and Apache ActiveMQ Artemis 1.0.0 to 2.44.0, and names one fix: 2.57.0, released on 9 September. Nothing earlier gets a patch. Four more Artemis CVEs were published the same day with the same range and the same single fix. Then on 26 September the ActiveMQ project marked ActiveMQ Classic 6.2 as end of life, with a final release that does not include September's Classic fix.

The five September Artemis CVEs

CVENVD CVSSApache ratingIssue
CVE-2026-579679.8ImportantCORE SESSION_REATTACH lets an attacker take over a session without authenticating
CVE-2026-493649.1ImportantA network-adjacent attacker captures cluster administrative credentials through discovery during the cluster connection handshake
CVE-2026-675939.1ImportantOpenWire RemoveSubscriptionInfo deletes a queue before authentication
CVE-2026-493627.5ImportantCORE protocol lets unauthenticated clients create durable queues
CVE-2026-493637.5ModerateCORE SUBSCRIBE_TOPOLOGY discloses cluster node details before authentication

The NVD scores for all five come from CISA-ADP. None of the five needs credentials, so the broker's user and role settings do not protect against them. What matters until the upgrade is who can reach the acceptors, and the CORE and OpenWire protocols in particular. The advisories list no workaround.

Why there is no backport

Artemis does not run maintenance branches. Every release since 2.32.0 in January 2024 has been a new minor version, with no patch releases between them. The download page offers only the current release, and the September advisories name 2.57.0 alone. The project publishes no support policy beyond that, and endoflife.date describes it as having no clearly defined policy, with only the latest release appearing to be maintained. In practice a broker that is not on the newest release is not on a fixed release, and that will be true again the next time an advisory lands. See the Artemis end-of-life chart for the release history.

The rename, and what your scanner sees

In November 2025 the ActiveMQ PMC moved Artemis into its own top-level Apache project, Apache Artemis. The release after 2.44.0 (3 November 2025) was 2.50.0 (23 January 2026); there were no releases numbered 2.45 to 2.49. The advisories list two sets of Maven coordinates: org.apache.activemq:artemis-* for Apache ActiveMQ Artemis 1.0.0 to 2.44.0, and org.apache.artemis:artemis-* for Apache Artemis 2.50.0 to 2.56.0. A scanner or SBOM matcher that only knows one group ID will miss half of the affected range, so check that yours matches both.

Upgrading to 2.57.0

2.57.0 needs Java 17 or later. Artemis has required Java 17 since 2.39.0 in December 2024, and 2.38.0 and earlier ran on Java 11, so brokers pinned on Java 11 need a JDK upgrade first. Brokers embedded in an application move with that application's dependency tree.

Older pinned releases have one more item to check. CVE-2026-101292 (CVSS 8.2), published on NVD on 28 September with Red Hat as the CNA, is unsafe reflection in federation: an authenticated federation peer can make the broker load and instantiate arbitrary classes. It affects ActiveMQ Artemis before 2.34.0 and has been fixed since 2.34.0, released in June 2024, which matters to anyone still on 2.33 or older.

ActiveMQ Classic 6.2 reached end of life

The ActiveMQ Classic download page now lists 6.2.x as Inactive, which the project defines as having reached end of life with no further updates. The final release, 6.2.10, shipped on 26 September 2026; its release page describes a maintenance release that downgrades the bundled Camel to match the Spring version. The active Classic lines are 6.3.x (6.3.2, 2 September 2026) and 5.19.x (5.19.11, 5 September 2026). 5.18.x is inactive as well, with 5.18.7 as its last release; see ActiveMQ 5.18 end of life and the ActiveMQ Classic end-of-life chart.

6.2 ended with a fix missing. CVE-2026-74761 lets an authenticated client give another client's clientId when it removes a durable topic subscription. NVD published it on 9 September with a CVSS 3.1 score of 7.5 from CISA-ADP; Apache rates it moderate. The advisory lists 6.0.0 up to 6.3.2 as affected and names 5.19.11 and 6.3.2 as the fixes. 6.2.10 came out after it without the change: the TopicRegion fix is in 6.3.2, and TopicRegion in 6.2.10 is the same as in 6.2.9.

The ActiveMQ compatibility table lists Spring 6.2.19 and Jetty 11.0.26 under 6.2. Spring Framework 6.2 left open source support on 30 June 2026 and Jetty 11 is past the end of Jetty's community support, so the libraries under 6.2 no longer get public fixes either. Moving to 6.3 brings Spring 7.0 and Jetty 12.1, which matters most where the broker is embedded in a Spring application.

What to do

  • Artemis: move to 2.57.0 on Java 17 or later, and check that your scanner matches both group IDs. Until the upgrade, limit network access to the acceptors.
  • Classic 6.2: move to 6.3.2, allowing for the Spring 7.0 change.
  • Classic 5.18 or older: 5.19.11 carries the CVE-2026-74761 fix. The longer-term choice is between 6.x and Artemis; the Classic to Artemis migration guide covers the second.

Where OSSeva fits

OSSeva ships patched, signed builds for the Artemis 2.x release you are pinned on, with the September fixes backported, and for the ActiveMQ Classic 5.x and 6.x lines upstream no longer patches. They are delivered through your own repository manager on the Patch tier; Assure adds a VEX statement for each CVE; Operate adds 24/7 operation of the brokers. See ActiveMQ Classic extended support, the Artemis support page and the ActiveMQ support page.

Tags

ActiveMQ ArtemisActiveMQCVE-2026-57967CVEEnd of Life

Ready to get your open source under control?

Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.