Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-49363

Apache Artemis discloses cluster topology to unauthenticated CORE clients

Technology

ActiveMQ Artemis

CVSS Score

7.5 / 10.0

Affected Versions

Apache Artemis 2.50.0 to 2.56.0; Apache ActiveMQ Artemis 1.0.0 to 2.44.0

Upstream Fix

2.57.0

Published

September 10, 2026

OSSeva Coverage

Fixed upstream

Description

An unauthenticated client connecting over the CORE protocol can learn cluster node details by sending SUBSCRIBE_TOPOLOGY before it authenticates. Apache rates the issue moderate; the 7.5 score on NVD is from CISA-ADP.

Upstream record: NVD · CVE.org

Is your ActiveMQ Artemis deployment affected?

If you're running Apache Artemis 2.50.0 to 2.56.0; Apache ActiveMQ Artemis 1.0.0 to 2.44.0, you need this patch. Book a discovery call to get covered.