Description
When the broker is processing message-based management requests, sent by an authenticated messaging client that is authorized with MANAGE permission to perform management-via-messaging, the parameter processing can trigger Java deserialization of certain method parameters that the broker will not utilise. The permitted types allow to craft a payload causing excessive computation and pinning the processing thread, leading to denial of service.




This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.3.0 through 2.44.0.



Users are recommended to upgrade to version 2.57.0, which fixes the issue.
Published: 2026-09-10
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The flaw resides in the processing of message‑based management requests. When a client authenticated with MANAGE permission sends a specially crafted parameter, the broker deserializes the value even though it is not needed for execution. This unintended deserialization can trigger excessive computation and lock the processing thread, causing denial of service to the broker for legitimate users. The vulnerability does not provide remote code execution or compromise confidentiality; it solely disrupts service availability for those who possess the required permissions.

Affected Systems

Apache Artemis versions 2.50.0 through 2.56.0 and Apache ActiveMQ Artemis versions 1.3.0 through 2.44.0 are affected. The fix is included in Apache Artemis 2.57.0; ActiveMQ Artemis can be updated to a release that incorporates this Artemis 2.57.0 patch.

Risk and Exploitability

The moderate severity. The EPSS score of <1% denotes a very low likelihood of exploitation. The attack requires an authenticated client with MANAGE permission, so the attacker must first obtain privileged access, limiting the threat sphere. The vulnerability is not listed in CISA KEV, but the lack of protection against deserialization of untrusted data keeps the risk significant for installations that enable message‑based management with elevated permissions.

Generated by OpenCVE AI on September 11, 2026 at 00:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Artemis to version 2.57.0 or later to apply the deserialization fix.
  • Upgrade ActiveMQ Artemis to the most recent release that incorporates the Artemis 2.57.0 security update; verify the release notes for the inclusion of this patch.
  • Restrict MANAGE permission to only trusted and minimal set of users and audit IAM policies to ensure that only designated administrators can issue message‑based management requests.

Generated by OpenCVE AI on September 11, 2026 at 00:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:apache:artemis:*:*:*:*:*:*:*:*

Thu, 10 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Thu, 10 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Thu, 10 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Thu, 10 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache activemq Artemis
Apache artemis
Vendors & Products Apache
Apache activemq Artemis
Apache artemis

Thu, 10 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
CWE-502

Thu, 10 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
References

Thu, 10 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Description When the broker is processing message-based management requests, sent by an authenticated messaging client that is authorized with MANAGE permission to perform management-via-messaging, the parameter processing can trigger Java deserialization of certain method parameters that the broker will not utilise. The permitted types allow to craft a payload causing excessive computation and pinning the processing thread, leading to denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.3.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.
Title Apache Artemis, Apache ActiveMQ Artemis: Message-based management parameter deserialization may lead to denial of service
References

Subscriptions

Apache Activemq Artemis Artemis
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-10T15:53:35.376Z

Reserved: 2026-06-25T13:00:37.878Z

Link: CVE-2026-57822

cve-icon Vulnrichment

Updated: 2026-09-10T05:11:46.447Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T05:17:01.343

Modified: 2026-09-16T01:10:26.913

Link: CVE-2026-57822

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-10T05:47:50Z

Links: CVE-2026-57822 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T00:45:11Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data