Credential Exposure in Apache Artemis and ActiveMQ by Apache
CVE-2026-49364

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
10 September 2026

What is CVE-2026-49364?

An unauthenticated network-adjacent attacker can exploit a weakness during the initial cluster connection handshake, leading to the capture of critical cluster administrative credentials. This vulnerability impacts specific versions of Apache Artemis and ActiveMQ Artemis, necessitating urgent upgrades to version 2.57.0 to mitigate risks.

Affected Version(s)

Apache ActiveMQ Artemis 1.0.0 <= 2.44.0

Apache ActiveMQ Artemis 1.0.0 <= 2.44.0

Apache Artemis 2.50.0 <= 2.56.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Domenico Francesco Bruscino
.