Description
An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker state manipulation and potential denial of service.

This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0.



Users are recommended to upgrade to version 2.57.0, which fixes the issue.
Published: 2026-09-10
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Queue Creation
Action: Apply Patch
AI Analysis

Impact

The vulnerability allows an attacker without credentials to create durable queues via the CORE protocol, thereby altering broker state and potentially disrupting messaging services. The flaw arises from missing authentication checks when processing queue creation requests, classified as CWE‑306. Because of the lack of required credentials, remote actors can manipulate queue configuration and block legitimate traffic, leading to denial of service and arbitrary resource consumption. The official CVSS score of 7.5 indicates high severity, while the EPSS score of <1% suggests that exploitation attempts are currently rare. The vulnerability is not listed in the CISA KEV catalog, implying no documented active exploitation at the time of this analysis.

Affected Systems

Apache Artemis versions 2.50.0 through 2.56.0 and Apache ActiveMQ Artemis versions 1.0.0 through 2.44.0 are affected when exposed to untrusted networks enabling the CORE protocol. Any deployment of these versions that accepts inbound CORE connections is susceptible to queue manipulation without authentication.

Risk and Exploitability

An attacker can initiate a connection over the CORE protocol, send a queue creation command, and have it accepted without verification of credentials. This leads to unauthorized creation of durable queues and possible broker state contamination. Because the entry point is remote and does not require prior authentication, the risk surface is in public or semi‑public IP spaces where CORE endpoints are reachable. The low EPSS score indicates a low likelihood of exploitation, but the high CVSS score and complete lack of authentication make the risk significant for exposed brokers. The lack of a KEV listing suggests no known active exploitation, yet the impact remains considerable for any exposed environment.

Generated by OpenCVE AI on September 11, 2026 at 00:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Artemis to version 2.57.0 or later, which contains the fix for the missing authentication in the CORE protocol handler.
  • Upgrade Apache ActiveMQ Artemis to the latest release that includes the authentication fix, ensuring that the vulnerable queue creation path is secured.
  • Restrict CORE protocol access with firewall rules or network segmentation so that only trusted hosts can reach the broker, thereby limiting exposure to potential attackers.

Generated by OpenCVE AI on September 11, 2026 at 00:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:apache:artemis:*:*:*:*:*:*:*:*

Thu, 10 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Thu, 10 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H'}

threat_severity

Important


Thu, 10 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache activemq Artemis
Apache artemis
Vendors & Products Apache
Apache activemq Artemis
Apache artemis

Thu, 10 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
References

Thu, 10 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Description An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker state manipulation and potential denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.
Title Apache Artemis, Apache ActiveMQ Artemis: Missing Authentication in CORE Protocol Handler Allows Unauthorized Queue Creation
Weaknesses CWE-306
References

Subscriptions

Apache Activemq Artemis Artemis
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-10T15:56:53.805Z

Reserved: 2026-05-29T16:31:29.814Z

Link: CVE-2026-49362

cve-icon Vulnrichment

Updated: 2026-09-10T05:11:20.822Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T05:16:59.747

Modified: 2026-09-16T01:10:42.343

Link: CVE-2026-49362

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-10T05:35:46Z

Links: CVE-2026-49362 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T00:45:11Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function