CVE-2026-49364
A critical vulnerability (CVE-2026-49364) allows unauthenticated attackers to capture cluster administrative credentials during the initial connection handshake in Apache Artemis and Apache ActiveMQ Artemis. The issue affects versions 2.50.0–2.56.0 of Artemis and 1.0.0–2.44.0 of ActiveMQ Artemis, and is resolved by upgrading to version 2.57.0.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Apache Artemis (versions 2.50.0 through 2.56.0) and Apache ActiveMQ Artemis (versions 1.0.0 through 2.44.0)
Real-world impact
An unauthenticated network-adjacent attacker can use discovery mechanisms to steal cluster administrative credentials during the first connection handshake, potentially leading to full compromise of the cluster.
Why this severity
Critical (CVSS base score: 9.1) due to high severity (C:H), high impact (I:H), and no privilege requirements (A:N).
What to do about it
- 01Upgrade Apache Artemis from version 2.50.0 through 2.56.0 to version 2.57.0 or later.
- 02Upgrade Apache ActiveMQ Artemis from version 1.0.0 through 2.44.0 to version 2.57.0 or later.
Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0 – Users are recommended to upgrade to version 2.57.0, which fixes the issue. (NVD description)
Timeline
- Sep 10, 2026 · 4d agoPublishedDisclosed and added to the National Vulnerability Database.
- Sep 10, 2026 · 3d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.