Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2026-40914

Apache Artemis: STOMP user can change an address's routing type without createAddress

Technology

ActiveMQ Artemis

CVSS Score

4.3 / 10.0

Affected Versions

Apache Artemis 2.50.0 to 2.53.0; Apache ActiveMQ Artemis 2.0.0 to 2.44.0

Upstream Fix

2.54.0

Published

May 28, 2026

OSSeva Coverage

Fixed upstream

Description

A STOMP client whose credentials grant send or consume permission on an address can add a routing type the address does not support, even without the createAddress permission, and then send to or consume from it. Apache rates it low.

Upstream record: NVD · CVE.org

Is your ActiveMQ Artemis deployment affected?

If you're running Apache Artemis 2.50.0 to 2.53.0; Apache ActiveMQ Artemis 2.0.0 to 2.44.0, you need this patch. Book a discovery call to get covered.