Description
An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake.

This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0.



Users are recommended to upgrade to version 2.57.0, which fixes the issue.
Published: 2026-09-10
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Credential Exposure
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows a network‑adjacent attacker to obtain cluster administrative credentials during the initial handshake in Apache Artemis and ActiveMQ Artemis. Because the connection does not require authentication at this stage, plaintext credentials can be captured. This results in unauthorized disclosure of privileged credentials, enabling an attacker to perform actions with administrative authority within the cluster. The weakness corresponds to CWE‑306, which denotes authentication bypass.

Affected Systems

Affected are Apache Artemis versions 2.50.0 through 2.56.0 and Apache ActiveMQ Artemis versions 1.0.0 through 2.44.0. Administrators using these releases should immediately verify their installed version against these ranges.

Risk and Exploitability

The exploitation requires only a presence on the same network segment as the cluster; no credentials are needed to initiate the connection. The attack relies on capturing data during the initial handshake, which is performed automatically when peers discover each other. The EPSS score of <1% indicates a low but nonzero probability that the vulnerability will be exploited in the wild. The updated CVSS score of 9.1 reflects critical severity, and the vulnerability remains unlisted in CISA KEV, so the exact likelihood of exploitation cannot be quantified. However, because credentials are transmitted openly and no user interaction is necessary, the risk of credential theft is significant for systems that expose the cluster ports to untrusted network traffic.

Generated by OpenCVE AI on September 11, 2026 at 00:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Artemis and ActiveMQ Artemis to version 2.57.0, which removes the credential exposure flaw.
  • If an upgrade is not immediately possible, limit cluster discovery and communication to trusted internal networks only, and block the relevant ports from external sources.
  • Apply firewall or network segmentation to ensure that only authorized hosts can reach the cluster peer ports.
  • Enable client‑side authentication or TLS to encrypt communications and verify peer identity, if supported by the product.

Generated by OpenCVE AI on September 11, 2026 at 00:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:apache:artemis:*:*:*:*:*:*:*:*

Thu, 10 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.0, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Thu, 10 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.0, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Important


Thu, 10 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache activemq Artemis
Apache artemis
Vendors & Products Apache
Apache activemq Artemis
Apache artemis

Thu, 10 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
References

Thu, 10 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Description An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.
Title Apache Artemis, Apache Artemis, Apache ActiveMQ Artemis, Apache ActiveMQ Artemis: Pre-Authentication Cluster Credential Exposure to Discovered Peers
Weaknesses CWE-306
References

Subscriptions

Apache Activemq Artemis Artemis
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-10T15:54:25.139Z

Reserved: 2026-05-29T16:34:41.640Z

Link: CVE-2026-49364

cve-icon Vulnrichment

Updated: 2026-09-10T05:11:25.133Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T05:17:01.230

Modified: 2026-09-16T01:10:31.487

Link: CVE-2026-49364

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-10T05:38:15Z

Links: CVE-2026-49364 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T00:45:11Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function