Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-49362

Apache Artemis CORE protocol handler lets unauthenticated clients create durable queues

Technology

ActiveMQ Artemis

CVSS Score

7.5 / 10.0

Affected Versions

Apache Artemis 2.50.0 to 2.56.0; Apache ActiveMQ Artemis 1.0.0 to 2.44.0

Upstream Fix

2.57.0

Published

September 10, 2026

OSSeva Coverage

Fixed upstream

Description

An unauthenticated remote attacker can create arbitrary durable queues over the CORE protocol, changing broker state without permission and potentially denying service.

Upstream record: NVD · CVE.org

Is your ActiveMQ Artemis deployment affected?

If you're running Apache Artemis 2.50.0 to 2.56.0; Apache ActiveMQ Artemis 1.0.0 to 2.44.0, you need this patch. Book a discovery call to get covered.