Description
An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node details by sending a SUBSCRIBE_TOPOLOGY request prior to authentication.



This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0.



Users are recommended to upgrade to version 2.57.0, which fixes the issue.
Published: 2026-09-10
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

A remote attacker who has not yet authenticated can exploit the CORE protocol by sending a SUBSCRIBE_TOPOLOGY of the cluster topology including node identities. This information disclosure (CWE‑306) can aid attackers in mapping the environment, facilitating further targeted attacks.

Affected Systems

Apache Software Foundation’s Apache Artemis is vulnerable in versions 2.50.0 through 2.56.0. Apache ActiveMQ Artemis is affected from 1.0.0 through 2.44.0. No other vendors or product lines are listed as impacted.

Risk and Exploitability

The vulnerability requires only an unauthenticated network connection The CVSS score of 7.5 indicates a high severity assessment. The EPSS score of < 1% indicates a very low exploitation probability, and the flaw is not listed in CISA KEV. The potential for pre‑authentication data leakage is significant. Attackers could use the disclosed topology information to identify high‑value nodes or plan further intrusions. The impact is primarily confidentiality loss of cluster configuration information.

Generated by OpenCVE AI on September 11, 2026 at 00:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Artemis to version 2.57.0 or later, which includes the fix.
  • Restrict network access to the broker’s CORE protocol port to trusted hosts or VPNs.
  • Monitor broker logs for anomalous SUBSCRIBE_TOPOLOGY requests to detect potential exploitation attempts.
  • For Apache ActiveMQ Artemis, consider applying interim network restrictions or blocking the CORE protocol until vendor releases a fix, as no patch is currently available.

Generated by OpenCVE AI on September 11, 2026 at 00:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:apache:artemis:*:*:*:*:*:*:*:*

Thu, 10 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Thu, 10 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache activemq Artemis
Apache artemis
Vendors & Products Apache
Apache activemq Artemis
Apache artemis

Thu, 10 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

threat_severity

Moderate


Thu, 10 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
References

Thu, 10 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Description An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node details by sending a SUBSCRIBE_TOPOLOGY request prior to authentication. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.
Title Apache Artemis, Apache ActiveMQ Artemis: Pre-Authentication Information Disclosure in CORE Protocol Topology Subscription
Weaknesses CWE-306
References

Subscriptions

Apache Activemq Artemis Artemis
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-10T15:55:22.267Z

Reserved: 2026-05-29T16:33:06.443Z

Link: CVE-2026-49363

cve-icon Vulnrichment

Updated: 2026-09-10T05:11:23.010Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T05:17:01.123

Modified: 2026-09-16T01:10:36.583

Link: CVE-2026-49363

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-10T05:46:38Z

Links: CVE-2026-49363 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T00:45:11Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function