Missing Authentication for Critical Function in Apache ActiveMQ Artemis and Apache Artemis - CVE-2026-49362
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote attacker to manipulate broker state and cause a denial of service.
The vulnerability exists due to missing authentication in the CORE protocol handler when processing CORE protocol requests. A remote attacker can create arbitrary durable queues to manipulate broker state and cause a denial of service.
Affected software
Apache Artemis