Missing Authentication for Critical Function in Apache ActiveMQ Artemis and Apache Artemis - CVE-2026-49363
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose cluster node details.
The vulnerability exists due to missing authentication in the CORE protocol topology subscription feature when sending a SUBSCRIBE_TOPOLOGY request prior to authentication. A remote attacker can send a SUBSCRIBE_TOPOLOGY request to disclose cluster node details.
Affected software
Apache Artemis