Apache Artemis: Unauth Capture via Cluster Handshake (2.50-2.56, 1.0-2.44)
CVE-2026-49364 Published on September 10, 2026
Apache Artemis, Apache Artemis, Apache ActiveMQ Artemis, Apache ActiveMQ Artemis: Pre-Authentication Cluster Credential Exposure to Discovered Peers
An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake.
This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0.
Users are recommended to upgrade to version 2.57.0, which fixes the issue.
Weakness Type
Missing Authentication for Critical Function
The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Products Associated with CVE-2026-49364
Want to know whenever a new CVE is published for Apache Activemq Artemis? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache Artemis:- Version 2.50.0, <= 2.56.0 is affected.
- Version 2.50.0, <= 2.56.0 is affected.
- Version 1.0.0, <= 2.44.0 is affected.
- Version 1.0.0, <= 2.44.0 is affected.