Impact
The vulnerability allows an attacker without credentials to create durable queues via the CORE protocol, thereby altering broker state and potentially disrupting messaging services. The flaw arises from missing authentication checks when processing queue creation requests, classified as CWE‑306. Because of the lack of required credentials, remote actors can manipulate queue configuration and block legitimate traffic, leading to denial of service and arbitrary resource consumption. The official CVSS score of 7.5 indicates high severity, while the EPSS score of <1% suggests that exploitation attempts are currently rare. The vulnerability is not listed in the CISA KEV catalog, implying no documented active exploitation at the time of this analysis.
Affected Systems
Apache Artemis versions 2.50.0 through 2.56.0 and Apache ActiveMQ Artemis versions 1.0.0 through 2.44.0 are affected when exposed to untrusted networks enabling the CORE protocol. Any deployment of these versions that accepts inbound CORE connections is susceptible to queue manipulation without authentication.
Risk and Exploitability
An attacker can initiate a connection over the CORE protocol, send a queue creation command, and have it accepted without verification of credentials. This leads to unauthorized creation of durable queues and possible broker state contamination. Because the entry point is remote and does not require prior authentication, the risk surface is in public or semi‑public IP spaces where CORE endpoints are reachable. The low EPSS score indicates a low likelihood of exploitation, but the high CVSS score and complete lack of authentication make the risk significant for exposed brokers. The lack of a KEV listing suggests no known active exploitation, yet the impact remains considerable for any exposed environment.
OpenCVE Enrichment