Remote Information Disclosure in Apache Artemis and ActiveMQ Products
CVE-2026-49363
Currently unrated
Key Information:
- Vendor
Apache
- Vendor
- CVE Published:
- 10 September 2026
What is CVE-2026-49363?
A vulnerability in Apache Artemis and ActiveMQ allows an unauthenticated remote attacker to gain sensitive information about cluster node details. By leveraging the CORE protocol, attackers can send a SUBSCRIBE_TOPOLOGY request prior to authentication, potentially exposing critical configuration and operational details without proper access controls. Users are advised to update to version 2.57.0, which addresses this security issue.
Affected Version(s)
Apache ActiveMQ Artemis 1.0.0 <= 2.44.0
Apache Artemis 2.50.0 <= 2.56.0