Credential Exposure in Apache Artemis and ActiveMQ by Apache
CVE-2026-49364

9.1CRITICAL

Key Information:

Vendor

Apache

Vendor
CVE Published:
10 September 2026

What is CVE-2026-49364?

An unauthenticated network-adjacent attacker can exploit a weakness during the initial cluster connection handshake, leading to the capture of critical cluster administrative credentials. This vulnerability impacts specific versions of Apache Artemis and ActiveMQ Artemis, necessitating urgent upgrades to version 2.57.0 to mitigate risks.

Affected Version(s)

Apache ActiveMQ Artemis 1.0.0 <= 2.44.0

Apache ActiveMQ Artemis 1.0.0 <= 2.44.0

Apache Artemis 2.50.0 <= 2.56.0

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Domenico Francesco Bruscino
.