CVE-2026-49362

Source
https://cve.org/CVERecord?id=CVE-2026-49362
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-49362.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-49362
Downstream
Published
2026-09-10T04:56:19Z
Modified
2026-09-17T03:47:28Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Apache Artemis, Apache ActiveMQ Artemis: Missing Authentication in CORE Protocol Handler Allows Unauthorized Queue Creation
Details

An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker state manipulation and potential denial of service.

This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0.

Users are recommended to upgrade to version 2.57.0, which fixes the issue.

Database specific
{
    "cna_assigner": "apache",
    "cwe_ids": [
        "CWE-306"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/49xxx/CVE-2026-49362.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "2.50.0"
                },
                {
                    "last_affected": "2.56.0"
                },
                {
                    "introduced": "1.0.0"
                },
                {
                    "last_affected": "2.44.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        },
        {
            "extracted_events": [
                {
                    "introduced": "2.50.0"
                },
                {
                    "fixed": "2.56.0"
                },
                {
                    "introduced": "1.0.0"
                },
                {
                    "fixed": "2.44.0"
                }
            ],
            "source": "DESCRIPTION"
        }
    ]
}
References

Affected packages

Git / github.com/apache/artemis

Affected ranges

Type
GIT
Repo
https://github.com/apache/artemis
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:apache:artemis:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "1.0.0"
        },
        {
            "fixed": "2.44.0"
        },
        {
            "introduced": "2.50.0"
        },
        {
            "fixed": "2.57.0"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

1.*
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.5.0
1.5.1
2.*
2.0.0
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.25.0
2.26.0
2.27.0
2.28.0
2.29.0
2.3.0
2.30.0
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.34.0
2.35.0
2.36.0
2.37.0
2.38.0
2.39.0
2.4.0
2.40.0
2.41.0
2.42.0
2.43.0
2.5.0
2.50.0
2.51.0
2.53.0
2.54.0
2.55.0
2.56.0
2.6.0
2.7.0
2.8.0
2.8.1
2.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-49362.json"