SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-49362

HIGH · CVSS 7.5 EPSS 0.42%

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Apache Artemis and Apache ActiveMQ Artemis are vulnerable to an unauthenticated remote attack that allows the creation of arbitrary durable queues via the CORE protocol, potentially leading to unauthorized manipulation of the broker state and denial of service. Organizations using affected versions (2.50.0 to 2.56.0 for Apache Artemis and 1.0.0 to 2.44.0 for ActiveMQ Artemis) should prioritize upgrading to version 2.57.0 to mitigate this risk.

CVE
CVE-2026-49362
Severity
HIGH
CVSS
7.5
EPSS
0.42%
Apache

Original NVD Description

An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker state manipulation and potential denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.