Impact
The vulnerability allows a network‑adjacent attacker to obtain cluster administrative credentials during the initial handshake in Apache Artemis and ActiveMQ Artemis. Because the connection does not require authentication at this stage, plaintext credentials can be captured. This results in unauthorized disclosure of privileged credentials, enabling an attacker to perform actions with administrative authority within the cluster. The weakness corresponds to CWE‑306, which denotes authentication bypass.
Affected Systems
Affected are Apache Artemis versions 2.50.0 through 2.56.0 and Apache ActiveMQ Artemis versions 1.0.0 through 2.44.0. Administrators using these releases should immediately verify their installed version against these ranges.
Risk and Exploitability
The exploitation requires only a presence on the same network segment as the cluster; no credentials are needed to initiate the connection. The attack relies on capturing data during the initial handshake, which is performed automatically when peers discover each other. The EPSS score of <1% indicates a low but nonzero probability that the vulnerability will be exploited in the wild. The updated CVSS score of 9.1 reflects critical severity, and the vulnerability remains unlisted in CISA KEV, so the exact likelihood of exploitation cannot be quantified. However, because credentials are transmitted openly and no user interaction is necessary, the risk of credential theft is significant for systems that expose the cluster ports to untrusted network traffic.
OpenCVE Enrichment